<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd" pub_date="2012-02-13" nvd_xml_version="1.2">
  <entry type="CVE" severity="Medium" seq="2003-0001" published="2003-01-17" name="CVE-2003-0001" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/412115" source="CERT-VN" adv="1">VU#412115</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-025.html" source="REDHAT">RHSA-2003:025</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf" source="MISC">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a010603-1.txt" source="ATSTAKE" adv="1">A010603-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104222046632243&amp;w=2" source="BUGTRAQ" adv="1">20030110 More information regarding Etherleak</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html" source="VULNWATCH">20030110 More information regarding Etherleak</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded" source="BUGTRAQ">20030117 Re: More information regarding Etherleak</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded" source="BUGTRAQ">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-088.html" source="REDHAT">RHSA-2003:088</ref>
      <ref url="http://www.osvdb.org/9962" source="OSVDB">9962</ref>
      <ref url="http://secunia.com/advisories/7996" source="SECUNIA">7996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665" source="OVAL" sig="1">oval:org.mitre.oval:def:2665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0002" published="2003-02-07" name="CVE-2003-0002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-002.asp" source="MS" patch="1" adv="1">MS03-002</ref>
      <ref url="http://www.iss.net/security_center/static/10318.php" source="XF" patch="1" adv="1">mcms-manuallogin-reasontxt-xss (10318)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103417794800719&amp;w=2" source="BUGTRAQ" adv="1">20021007 CSS on Microsoft Content Management Server</ref>
      <ref url="http://www.securityfocus.com/bid/5922" source="BID">5922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="content_management_server">
        <vers num="2001" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0003" published="2003-02-07" name="CVE-2003-0003" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/610986" source="CERT-VN" patch="1" adv="1">VU#610986</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-03.html" source="CERT" patch="1" adv="1">CA-2003-03</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-001.asp" source="MS" patch="1" adv="1">MS03-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11132" source="XF" adv="1">win-locator-bo(11132)</ref>
      <ref url="http://www.securityfocus.com/bid/6666" source="BID">6666</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104393588232166&amp;w=2" source="NTBUGTRAQ">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394414713415&amp;w=2" source="BUGTRAQ">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:103" source="OVAL" sig="1">oval:org.mitre.oval:def:103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":server:jp" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0004" published="2003-02-19" name="CVE-2003-0004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-005.asp" source="MS" patch="1" adv="1">MS03-005</ref>
      <ref url="http://www.securityfocus.com/bid/6778" source="BID">6778</ref>
      <ref url="http://www.iss.net/security_center/static/11260.php" source="XF">winxp-windows-redirector-bo(11260)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878038418534&amp;w=2" source="BUGTRAQ">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html" source="VULNWATCH">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0007" published="2003-02-07" name="CVE-2003-0007" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-003.asp" source="MS" patch="1" adv="1">MS03-003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11133" source="XF">outlook-v1-certificate-plaintext(11133)</ref>
      <ref url="http://www.securityfocus.com/bid/6667" source="BID">6667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0009" published="2003-03-07" name="CVE-2003-0009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/489721" source="CERT-VN">VU#489721</ref>
      <ref url="http://www.securityfocus.com/bid/6966" source="BID" patch="1" adv="1">6966</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-006.asp" source="MS" patch="1" adv="1">MS03-006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636383018686&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</ref>
      <ref url="http://www.iss.net/security_center/static/11425.php" source="XF" adv="1">winme-hsc-hcp-bo(11425)</ref>
      <ref url="http://www.osvdb.org/6074" source="OSVDB">6074</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-047.shtml" source="CIAC">N-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0010" published="2003-03-24" name="CVE-2003-0010" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7146" source="BID" patch="1" adv="1">7146</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-008.asp" source="MS" patch="1" adv="1">MS03-008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104812108307645&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html" source="VULNWATCH">20030319 Windows Scripting Engine issue</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26" source="IDEFENSE">20030319 Heap Overflow in Windows Script Engine</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:795" source="OVAL" sig="1">oval:org.mitre.oval:def:795</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:794" source="OVAL" sig="1">oval:org.mitre.oval:def:794</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:200" source="OVAL" sig="1">oval:org.mitre.oval:def:200</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:134" source="OVAL" sig="1">oval:org.mitre.oval:def:134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0011" published="2003-03-24" name="CVE-2003-0011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7145" source="BID" patch="1" adv="1">7145</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-009.asp" source="MS" patch="1" adv="1">MS03-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0012" published="2003-01-17" name="CVE-2003-0012" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
      <ref url="http://www.iss.net/security_center/static/10971.php" source="XF" adv="1">bugzilla-mining-world-writable(10971)</ref>
      <ref url="http://www.securityfocus.com/bid/6502" source="BID">6502</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-012.html" source="REDHAT">RHSA-2003:012</ref>
      <ref url="http://www.debian.org/security/2003/dsa-230" source="DEBIAN">DSA-230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.17" />
        <vers num="2.17.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0013" published="2003-01-17" name="CVE-2003-0013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-230" source="DEBIAN" patch="1" adv="1">DSA-230</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/6501" source="BID">6501</ref>
      <ref url="http://www.osvdb.org/6351" source="OSVDB">6351</ref>
      <ref url="http://www.iss.net/security_center/static/10970.php" source="XF">bugzilla-htaccess-database-password(10970)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.17" />
        <vers num="2.17.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0014" published="2003-01-11" name="CVE-2003-0014" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <sols>
      <sol source="nvd">For the stable distribution this problem has been fixed in version 1.2-14.2. For the unstable distribution this problem has been fixed in version 1.2-17.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18823" source="XF" patch="1" adv="1">bmv-symlink(18823)</ref>
      <ref url="http://securityfocus.org/bid/12229" source="BID" patch="1" adv="1">12229</ref>
      <ref url="http://www.debian.org/security/2005/dsa-633" source="DEBIAN" adv="1">DSA-633</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog" source="CONFIRM" adv="1">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</ref>
      <ref url="http://securitytracker.com/id?1012847" source="SECTRACK">1012847</ref>
      <ref url="http://secunia.com/advisories/13796" source="SECUNIA">13796</ref>
      <ref url="http://secunia.com/advisories/13793" source="SECUNIA">13793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmv" name="bmv">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0015" published="2003-02-07" name="CVE-2003-0015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/650937" source="CERT-VN" adv="1">VU#650937</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-02.html" source="CERT">CA-2003-02</ref>
      <ref url="http://security.e-matters.de/advisories/012003.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012003.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-013.html" source="REDHAT" patch="1" adv="1">RHSA-2003:013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11108" source="XF" adv="1">cvs-doublefree-memory-corruption(11108)</ref>
      <ref url="http://www.securityfocus.com/bid/6650" source="BID">6650</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-012.html" source="REDHAT">RHSA-2003:012</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009" source="MANDRAKE">MDKSA-2003:009</ref>
      <ref url="http://www.debian.org/security/2003/dsa-233" source="DEBIAN">DSA-233</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-032.shtml" source="CIAC">N-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104438807203491&amp;w=2" source="FREEBSD">FreeBSD-SA-03:01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428571204468&amp;w=2" source="BUGTRAQ">20030202 Exploit for CVS double free() for Linux pserver</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342550612736&amp;w=2" source="BUGTRAQ">20030124 Test program for CVS double-free.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104333092200589&amp;w=2" source="BUGTRAQ">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</ref>
      <ref url="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14" source="CONFIRM">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html" source="VULNWATCH">20030120 Advisory 01/2003: CVS remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.1p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0016" published="2003-02-07" name="CVE-2003-0016" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/979793" source="CERT-VN">VU#979793</ref>
      <ref url="http://www.kb.cert.org/vuls/id/825177" source="CERT-VN">VU#825177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" source="MLIST" patch="1">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</ref>
      <ref url="http://www.apacheweek.com/issues/03-01-24#security" source="CONFIRM">http://www.apacheweek.com/issues/03-01-24#security</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11125" source="XF">apache-device-code-execution(11125)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11124" source="XF">apache-device-name-dos(11124)</ref>
      <ref url="http://www.securityfocus.com/bid/6659" source="BID">6659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0017" published="2003-02-07" name="CVE-2003-0017" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" source="CONFIRM" patch="1">http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0018" published="2003-02-19" name="CVE-2003-0018" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-025.html" source="REDHAT" patch="1" adv="1">RHSA-2003:025</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.iss.net/security_center/static/11249.php" source="XF" adv="1">linux-odirect-information-leak(11249)</ref>
      <ref url="http://www.securityfocus.com/bid/6763" source="BID">6763</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014" source="MANDRAKE">MDKSA-2003:014</ref>
      <ref url="http://www.debian.org/security/2003/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0019" published="2003-02-19" name="CVE-2003-0019" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/134025" source="CERT-VN">VU#134025</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-056.html" source="REDHAT" patch="1" adv="1">RHSA-2003:056</ref>
      <ref url="http://www.iss.net/security_center/static/11276.php" source="XF" patch="1" adv="1">linux-umlnet-gain-privileges(11276)</ref>
      <ref url="http://www.securityfocus.com/bid/6801" source="BID">6801</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-044.shtml" source="CIAC">N-044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0020" published="2003-03-18" name="CVE-2003-0020" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9930" source="BID" patch="1" adv="1">9930</ref>
      <ref url="http://www.iss.net/security_center/static/11412.php" source="XF" adv="1">apache-esc-seq-injection(11412)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.trustix.org/errata/2004/0027" source="TRUSTIX">2004-0027</ref>
      <ref url="http://www.trustix.org/errata/2004/0017" source="TRUSTIX">2004-0017</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" source="SLACKWARE">SSA:2004-133</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-244.html" source="REDHAT">RHSA-2003:244</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-243.html" source="REDHAT">RHSA-2003:243</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-139.html" source="REDHAT">RHSA-2003:139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-104.html" source="REDHAT">RHSA-2003:104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-083.html" source="REDHAT">RHSA-2003:083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-082.html" source="REDHAT">RHSA-2003:082</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050" source="MANDRAKE">MDKSA-2003:050</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-22.xml" source="GENTOO">GLSA-200405-22</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" source="BUGTRAQ">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE">APPLE-SA-2004-05-03</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046" source="MANDRAKE">MDKSA-2004:046</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4114" source="OVAL" sig="1">oval:org.mitre.oval:def:4114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:150" source="OVAL" sig="1">oval:org.mitre.oval:def:150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100109" source="OVAL" sig="1">oval:org.mitre.oval:def:100109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0021" published="2003-03-03" name="CVE-2003-0021" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11413.php" source="XF" adv="1">terminal-emulator-screen-dump(11413)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6936" source="BID">6936</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" source="MANDRAKE">MDKSA-2003:040</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.8.10" />
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0022" published="2003-03-03" name="CVE-2003-0022" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11413.php" source="XF" adv="1">terminal-emulator-screen-dump(11413)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6938" source="BID">6938</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-055.html" source="REDHAT">RHSA-2003:055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-054.html" source="REDHAT">RHSA-2003:054</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" source="MANDRAKE">MDKSA-2003:034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.7.5" />
        <vers num="2.7.6" />
        <vers num="2.7.7" />
        <vers num="2.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0023" published="2003-03-03" name="CVE-2003-0023" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11416.php" source="XF" adv="1">terminal-emulator-menu-modification(11416)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6947" source="BID">6947</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-055.html" source="REDHAT">RHSA-2003:055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-054.html" source="REDHAT">RHSA-2003:054</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" source="MANDRAKE">MDKSA-2003:034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.7.5" />
        <vers num="2.7.6" />
        <vers num="2.7.7" />
        <vers num="2.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0024" published="2003-03-03" name="CVE-2003-0024" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11416.php" source="XF" adv="1">terminal-emulator-menu-modification(11416)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6949" source="BID">6949</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aterm" name="aterm">
        <vers num="0.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0025" published="2003-01-17" name="CVE-2003-0025" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-229" source="DEBIAN" patch="1" adv="1">DSA-229</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104204786206563&amp;w=2" source="BUGTRAQ" adv="1">20030108 IMP 2.x SQL injection vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/id?1005904" source="SECTRACK">1005904</ref>
      <ref url="http://www.securityfocus.com/bid/6559" source="BID">6559</ref>
      <ref url="http://www.securityfocus.com/archive/1/306268" source="BUGTRAQ">20030108 Re: IMP 2.x SQL injection vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/8177" source="SECUNIA">8177</ref>
      <ref url="http://secunia.com/advisories/8087" source="SECUNIA">8087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0026" published="2003-01-17" name="CVE-2003-0026" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/284857" source="CERT-VN" patch="1" adv="1">VU#284857</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-01.html" source="CERT" patch="1" adv="1">CA-2003-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-011.html" source="REDHAT" patch="1" adv="1">RHSA-2003:011</ref>
      <ref url="http://www.debian.org/security/2003/dsa-231" source="DEBIAN" patch="1" adv="1">DSA-231</ref>
      <ref url="http://www.suse.com/de/security/2003_006_dhcp.html" source="SUSE">SuSE-SA:2003:0006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11073" source="XF">dhcpd-minires-multiple-bo(11073)</ref>
      <ref url="http://www.suse.com/de/security/2003_006_dhcp.html" source="SUSE">SuSE-SA:2003:0006</ref>
      <ref url="http://www.securitytracker.com/id?1005924" source="SECTRACK">1005924</ref>
      <ref url="http://www.securityfocus.com/bid/6627" source="BID">6627</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html" source="OPENPKG">OpenPKG-SA-2003.002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007" source="MANDRAKE">MDKSA-2003:007</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-031.shtml" source="CIAC">N-031</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562" source="CONECTIVA">CLA-2003:562</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html" source="BUGTRAQ">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0" />
        <vers num="3.0.1" edition="rc1" />
        <vers num="3.0.1" edition="rc2" />
        <vers num="3.0.1" edition="rc3" />
        <vers num="3.0.1" edition="rc4" />
        <vers num="3.0.1" edition="rc5" />
        <vers num="3.0.1" edition="rc6" />
        <vers num="3.0.1" edition="rc7" />
        <vers num="3.0.1" edition="rc8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0027" published="2003-02-07" name="CVE-2003-0027" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/850785" source="CERT-VN" patch="1" adv="1">VU#850785</ref>
      <ref url="http://www.entercept.com/news/uspr/01-22-03.asp" source="MISC" patch="1" adv="1">http://www.entercept.com/news/uspr/01-22-03.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11129" source="XF">solaris-kcms-directory-traversal(11129)</ref>
      <ref url="http://www.securityfocus.com/bid/6665" source="BID">6665</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104" source="SUNALERT">50104</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104326556329850&amp;w=2" source="BUGTRAQ">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2592" source="OVAL" sig="1">oval:org.mitre.oval:def:2592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:195" source="OVAL" sig="1">oval:org.mitre.oval:def:195</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:120" source="OVAL" sig="1">oval:org.mitre.oval:def:120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0028" published="2003-03-25" name="CVE-2003-0028" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-10.html" source="CERT" patch="1" adv="1">CA-2003-10</ref>
      <ref url="http://www.kb.cert.org/vuls/id/516825" source="CERT-VN">VU#516825</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-089.html" source="REDHAT">RHSA-2003:089</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_027_glibc.html" source="SUSE">SuSE-SA:2003:027</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html" source="ENGARDE">ESA-20030321-010</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20030318.html" source="EEYE" adv="1">AD20030318</ref>
      <ref url="http://www.debian.org/security/2003/dsa-282" source="DEBIAN">DSA-282</ref>
      <ref url="http://www.debian.org/security/2003/dsa-272" source="DEBIAN">DSA-272</ref>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN">DSA-266</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878237121402&amp;w=2" source="TRUSTIX">2003-0014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104860855114117&amp;w=2" source="BUGTRAQ">20030325 GLSA:  glibc (200303-22)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811415301340&amp;w=2" source="BUGTRAQ">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104810574423662&amp;w=2" source="BUGTRAQ">20030319 EEYE: XDR Integer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html" source="VULNWATCH">20030319 EEYE: XDR Integer Overflow</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc" source="NETBSD">NetBSD-SA2003-008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316931/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: dietlibc (200303-29)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315638/30/25430/threaded" source="BUGTRAQ">20030319 RE: EEYE: XDR Integer Overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037" source="MANDRAKE">MDKSA-2003:037</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:230" source="OVAL" sig="1">oval:org.mitre.oval:def:230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
      </prod>
      <prod vendor="openafs" name="openafs">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.4a" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.1a" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.2a" />
        <vers num="1.2.2b" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
      </prod>
      <prod vendor="cray" name="unicos">
        <vers num="6.0" />
        <vers num="6.0e" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="8.3" />
        <vers num="9.0" />
        <vers num="9.0.2.5" />
        <vers num="9.2" />
        <vers num="9.2.4" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="stable" />
        <vers num="5.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
      <prod vendor="hp" name="hp-ux_series_700">
        <vers num="10.20" />
      </prod>
      <prod vendor="hp" name="hp-ux_series_800">
        <vers num="10.20" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0030" published="2003-03-18" name="CVE-2003-0030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/247545" source="CERT-VN" patch="1" adv="1">VU#247545</ref>
      <ref url="http://www.securityfocus.com/bid/7085" source="BID" adv="1">7085</ref>
      <ref url="http://www.securityfocus.com/bid/7084" source="BID" adv="1">7084</ref>
      <ref url="http://www.securityfocus.com/bid/7083" source="BID" adv="1">7083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104758650516677&amp;w=2" source="BUGTRAQ" adv="1">20030313 Protegrity buffer overflow</ref>
      <ref url="http://secunia.com/advisories/8294" source="SECUNIA">8294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="protegrity" name="secure.data">
        <vers num="2.2.3.7" />
        <vers num="2.2.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0031" published="2003-01-17" name="CVE-2003-0031" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-228" source="DEBIAN" patch="1" adv="1">DSA-228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030103 Multiple libmcrypt vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/id?1006181" source="SECTRACK">1006181</ref>
      <ref url="http://www.securityfocus.com/bid/6510" source="BID">6510</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2" source="BUGTRAQ">20030105 GLSA:  libmcrypt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" source="CONECTIVA">CLA-2003:567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcrypt" name="libmcrypt">
        <vers num="2.5.1_r4" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0032" published="2003-01-17" name="CVE-2003-0032" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-228" source="DEBIAN" patch="1" adv="1">DSA-228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030103 Multiple libmcrypt vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/10988.php" source="XF" adv="1">libmcrypt-libtool-memory-leak(10988)</ref>
      <ref url="http://www.securityfocus.com/bid/6512" source="BID">6512</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2" source="BUGTRAQ">20030105 GLSA:  libmcrypt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" source="CONECTIVA">CLA-2003:567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcrypt" name="libmcrypt">
        <vers num="2.5.1_r4" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0033" published="2003-03-07" name="CVE-2003-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/916785" source="CERT-VN" adv="1">VU#916785</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-13.html" source="CERT">CA-2003-13</ref>
      <ref url="http://www.securityfocus.com/bid/6963" source="BID" patch="1" adv="1">6963</ref>
      <ref url="http://www.iss.net/security_center/static/10956.php" source="XF" patch="1" adv="1">snort-rpc-fragment-bo(10956)</ref>
      <ref url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951" source="ISS" patch="1" adv="1">20030303 Snort RPC Preprocessing Vulnerability</ref>
      <ref url="http://www.osvdb.org/4418" source="OSVDB">4418</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029" source="MANDRAKE">MDKSA-2003:029</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html" source="ENGARDE">ESA-20030307-007</ref>
      <ref url="http://www.debian.org/security/2003/dsa-297" source="DEBIAN">DSA-297</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2" source="GENTOO">GLSA-200304-06</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716001503409&amp;w=2" source="GENTOO">GLSA-200303-6.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673386226064&amp;w=2" source="BUGTRAQ">20030303 Snort RPC Vulnerability (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snort" name="snort">
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0034" published="2003-02-07" name="CVE-2003-0034" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.21.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" source="VULNWATCH">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.securitytracker.com/id?1005959" source="SECTRACK">1005959</ref>
      <ref url="http://www.securityfocus.com/bid/6656" source="BID">6656</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" source="MANDRAKE">MDKSA-2003:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jean-jacques_sarton" name="mtink">
        <vers num="0.9.32" />
        <vers num="0.9.33" />
        <vers num="0.9.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0035" published="2003-02-07" name="CVE-2003-0035" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.21.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" source="VULNWATCH">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.securitytracker.com/id?1005959" source="SECTRACK">1005959</ref>
      <ref url="http://www.securityfocus.com/bid/6658" source="BID">6658</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded" source="BUGTRAQ">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" source="MANDRAKE">MDKSA-2003:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robert_krawitz" name="escputil">
        <vers num="1.15.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0036" published="2003-02-07" name="CVE-2003-0036" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.21.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" source="VULNWATCH">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.securitytracker.com/id?1005959" source="SECTRACK">1005959</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded" source="BUGTRAQ">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" source="MANDRAKE">MDKSA-2003:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rildo_pragana" name="ml85p">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0037" published="2003-02-07" name="CVE-2003-0037" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-244" source="DEBIAN" patch="1" adv="1">DSA-244</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11181" source="XF">noffle-multiple-bo(11181)</ref>
      <ref url="http://www.securityfocus.com/bid/6695" source="BID">6695</ref>
      <ref url="http://secunia.com/advisories/7955" source="SECUNIA">7955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noffle" name="noffle">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0038" published="2003-02-07" name="CVE-2003-0038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-436" source="DEBIAN" patch="1" adv="1">DSA-436</ref>
      <ref url="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt" source="CONFIRM" patch="1">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342745916111" source="BUGTRAQ" adv="1">20030124 Mailman: cross-site scripting bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11152" source="XF">mailman-email-variable-xss(11152)</ref>
      <ref url="http://www.securitytracker.com/id?1005987" source="SECTRACK">1005987</ref>
      <ref url="http://www.securityfocus.com/bid/6677" source="BID">6677</ref>
      <ref url="http://www.osvdb.org/9205" source="OSVDB">9205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0039" published="2003-02-07" name="CVE-2003-0039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/149953" source="CERT-VN">VU#149953</ref>
      <ref url="http://www.debian.org/security/2003/dsa-245" source="DEBIAN" patch="1" adv="1">DSA-245</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104310927813830&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030115 DoS against DHCP infrastructure with isc dhcrelay</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11187" source="XF" adv="1">dhcp-dhcrelay-dos(11187)</ref>
      <ref url="http://www.securityfocus.com/bid/6628" source="BID">6628</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-034.html" source="REDHAT">RHSA-2003:034</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html" source="BUGTRAQ">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616" source="CONECTIVA">CLSA-2003:616</ref>
      <ref url="http://cc.turbolinux.com/security/TLSA-2003-26.txt" source="TURBO">TLSA-2003-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0.1" edition="rc1" />
        <vers num="3.0.1" edition="rc10" />
        <vers num="3.0.1" edition="rc2" />
        <vers num="3.0.1" edition="rc3" />
        <vers num="3.0.1" edition="rc4" />
        <vers num="3.0.1" edition="rc5" />
        <vers num="3.0.1" edition="rc6" />
        <vers num="3.0.1" edition="rc7" />
        <vers num="3.0.1" edition="rc8" />
        <vers num="3.0.1" edition="rc9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0040" published="2003-02-19" name="CVE-2003-0040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6738" source="BID" patch="1" adv="1">6738</ref>
      <ref url="http://www.debian.org/security/2003/dsa-247" source="DEBIAN" patch="1" adv="1">DSA-247</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11213" source="XF">courierimap-authmysqllib-sql-injection(11213)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="double_precision_incorporated" name="courier_mta">
        <vers num="0.37.3" />
      </prod>
      <prod vendor="inter7" name="courier-imap">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0041" published="2003-02-19" name="CVE-2003-0041" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-020.html" source="REDHAT" patch="1" adv="1">RHSA-2003:020</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html" source="VULNWATCH">20030128 MIT Kerberos FTP client remote shell commands execution</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021" source="MANDRAKE">MDKSA-2003:021</ref>
      <ref url="http://secunia.com/advisories/8114" source="SECUNIA">8114</ref>
      <ref url="http://secunia.com/advisories/7979" source="SECUNIA">7979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos_ftp_client">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":i386" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":i386" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.2" edition=":ia64" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0042" published="2003-02-07" name="CVE-2003-0042" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-246" source="DEBIAN" patch="1" adv="1">DSA-246</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394568616290&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11194" source="XF">tomcat-null-directory-listing(11194)</ref>
      <ref url="http://www.securityfocus.com/bid/6721" source="BID">6721</ref>
      <ref url="http://www.securityfocus.com/advisories/5111" source="HP">HPSBUX0303-249</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-060.shtml" source="CIAC">N-060</ref>
      <ref url="http://secunia.com/advisories/7977" source="SECUNIA">7977</ref>
      <ref url="http://secunia.com/advisories/7972" source="SECUNIA">7972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0043" published="2003-02-07" name="CVE-2003-0043" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11195" source="XF" adv="1">tomcat-webxml-read-files(11195)</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref url="http://www.securityfocus.com/bid/6722" source="BID">6722</ref>
      <ref url="http://www.securityfocus.com/advisories/5111" source="HP">HPSBUX0303-249</ref>
      <ref url="http://www.debian.org/security/2003/dsa-246" source="DEBIAN">DSA-246</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-060.shtml" source="CIAC">N-060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0044" published="2003-02-07" name="CVE-2003-0044" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-246" source="DEBIAN" patch="1" adv="1">DSA-246</ref>
      <ref url="http://www.securityfocus.com/advisories/5111" source="HP">HPSBUX0303-249</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11196" source="XF">tomcat-web-app-xss(11196)</ref>
      <ref url="http://www.securityfocus.com/bid/6720" source="BID">6720</ref>
      <ref url="http://www.osvdb.org/9204" source="OSVDB">9204</ref>
      <ref url="http://www.osvdb.org/9203" source="OSVDB">9203</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-060.shtml" source="CIAC">N-060</ref>
      <ref url="http://secunia.com/advisories/7972" source="SECUNIA">7972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0045" published="2003-02-07" name="CVE-2003-0045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12102" source="XF" adv="1">jakarta-tomcat-msdos-dos(12102)</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0046" published="2003-02-19" name="CVE-2003-0046" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.28.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref url="http://www.celestialsoftware.net/telnet/beta_software.html" source="CONFIRM" adv="1">http://www.celestialsoftware.net/telnet/beta_software.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" source="BUGTRAQ">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref url="http://www.securitytracker.com/id?1006013" source="SECTRACK">1006013</ref>
      <ref url="http://www.securityfocus.com/bid/6725" source="BID">6725</ref>
      <ref url="http://www.osvdb.org/7686" source="OSVDB">7686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="celestial_software" name="absolutetelnet">
        <vers num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0047" published="2003-02-19" name="CVE-2003-0047" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.28.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" source="BUGTRAQ">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref url="http://www.securitytracker.com/id?1006012" source="SECTRACK">1006012</ref>
      <ref url="http://www.securitytracker.com/id?1006011" source="SECTRACK">1006011</ref>
      <ref url="http://www.securitytracker.com/id?1006010" source="SECTRACK">1006010</ref>
      <ref url="http://www.securityfocus.com/bid/6728" source="BID">6728</ref>
      <ref url="http://www.securityfocus.com/bid/6727" source="BID">6727</ref>
      <ref url="http://www.securityfocus.com/bid/6726" source="BID">6726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="van_dyke_technologies" name="entunnel">
        <vers prev="1" num="1.0.2" />
      </prod>
      <prod vendor="van_dyke_technologies" name="securecrt">
        <vers num="3.4.7" />
        <vers num="4.0.2" />
      </prod>
      <prod vendor="van_dyke_technologies" name="securefx">
        <vers num="2.0.4" />
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0048" published="2003-02-19" name="CVE-2003-0048" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.28.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref url="http://www.securitytracker.com/id?1006014" source="SECTRACK">1006014</ref>
      <ref url="http://www.securityfocus.com/bid/6724" source="BID">6724</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" source="BUGTRAQ">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers num="0.48" />
        <vers num="0.49" />
        <vers num="0.53" />
        <vers num="0.53b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0049" published="2003-03-03" name="CVE-2003-0049" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.iss.net/security_center/static/11333.php" source="XF" adv="1">macos-afp-unauthorized-access(11333)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6860" source="BID">6860</ref>
      <ref url="http://securitytracker.com/id?1006107" source="SECTRACK">1006107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0050" published="2003-03-07" name="CVE-2003-0050" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11401.php" source="XF" adv="1">quicktime-darwin-command-execution(11401)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6954" source="BID">6954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0051" published="2003-03-07" name="CVE-2003-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11402.php" source="XF" adv="1">quicktime-darwin-path-disclosure(11402)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6956" source="BID">6956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0052" published="2003-03-07" name="CVE-2003-0052" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11403.php" source="XF" adv="1">quicktime-darwin-directory-disclosure(11403)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6955" source="BID">6955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0053" published="2003-03-07" name="CVE-2003-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11404.php" source="XF" adv="1">quicktime-darwin-parsexml-xss(11404)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6958" source="BID">6958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0054" published="2003-03-07" name="CVE-2003-0054" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11405.php" source="XF" adv="1">quicktime-darwin-describe-xss(11405)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6960" source="BID">6960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0055" published="2003-03-07" name="CVE-2003-0055" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11406.php" source="XF" adv="1">quicktime-darwin-mp3-bo(11406)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6957" source="BID">6957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime_darwin_mp3_broadcaster">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0056" published="2003-02-19" name="CVE-2003-0056" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-252" source="DEBIAN" patch="1" adv="1">DSA-252</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428624705363&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030202 GLSA:  slocate</ref>
      <ref url="http://www.usg.org.uk/advisories/2003.001.txt" source="MISC" adv="1">http://www.usg.org.uk/advisories/2003.001.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11369" source="OVAL">oval:org.mitre.oval:def:11369</ref>
      <ref url="http://www.net-security.org/advisory.php?id=2010" source="CONECTIVA">CLA-2003:643</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015" source="MANDRAKE">MDKSA-2003:015</ref>
      <ref url="http://secunia.com/advisories/8749" source="SECUNIA">8749</ref>
      <ref url="http://secunia.com/advisories/8236" source="SECUNIA">8236</ref>
      <ref url="http://secunia.com/advisories/8118/" source="SECUNIA">8118</ref>
      <ref url="http://secunia.com/advisories/8007" source="SECUNIA">8007</ref>
      <ref url="http://secunia.com/advisories/7982" source="SECUNIA">7982</ref>
      <ref url="http://secunia.com/advisories/7947" source="SECUNIA">7947</ref>
      <ref url="http://secunia.com/advisories/10720" source="SECUNIA">10720</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-041.html" source="REDHAT">RHSA-2004:041</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104348607205691&amp;w=2" source="BUGTRAQ">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342864418213&amp;w=2" source="BUGTRAQ">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt" source="CALDERA">CSSA-2003-009.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="2.5" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0057" published="2003-02-19" name="CVE-2003-0057" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104369136703903&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030127 Hypermail buffer overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11158" source="XF">hypermail-long-hostname-bo(11158)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11157" source="XF">hypermail-mail-attachment-bo(11157)</ref>
      <ref url="http://www.securityfocus.com/bid/6690" source="BID">6690</ref>
      <ref url="http://www.securityfocus.com/bid/6689" source="BID">6689</ref>
      <ref url="http://www.debian.org/security/2003/dsa-248" source="DEBIAN">DSA-248</ref>
      <ref url="http://secunia.com/advisories/8030" source="SECUNIA">8030</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html" source="VULNWATCH">20030126 Hypermail buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hypermail" name="hypermail">
        <vers num="2.0b25" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0058" published="2003-02-19" name="CVE-2003-0058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/661243" source="CERT-VN" patch="1" adv="1">VU#661243</ref>
      <ref url="http://www.securityfocus.com/bid/6683" source="BID" patch="1" adv="1">6683</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/10099" source="XF">kerberos-kdc-null-pointer-dos(10099)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-168.html" source="REDHAT">RHSA-2003:168</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" source="MANDRAKE">MDKSA-2003:043</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142" source="SUNALERT">50142</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" source="CONECTIVA">CLSA-2003:639</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1110" source="OVAL" sig="1">oval:org.mitre.oval:def:1110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
      </prod>
      <prod vendor="sun" name="enterprise_authentication_mechanism">
        <vers num="1.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0059" published="2003-02-19" name="CVE-2003-0059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/684563" source="CERT-VN" patch="1" adv="1">VU#684563</ref>
      <ref url="http://www.securityfocus.com/bid/6714" source="BID" patch="1" adv="1">6714</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11188" source="XF">kerberos-kdc-user-spoofing(11188)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-168.html" source="REDHAT">RHSA-2003:168</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" source="MANDRAKE">MDKSA-2003:043</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" source="CONECTIVA">CLSA-2003:639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0060" published="2003-02-19" name="CVE-2003-0060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/787523" source="CERT-VN" patch="1" adv="1">VU#787523</ref>
      <ref url="http://www.securityfocus.com/bid/6712" source="BID" patch="1" adv="1">6712</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11189" source="XF">kerberos-kdc-format-string(11189)</ref>
      <ref url="http://www.osvdb.org/4879" source="OSVDB">4879</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" source="CONECTIVA">CLSA-2003:639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0061" published="2002-01-11" name="CVE-2003-0061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0062" published="2003-02-19" name="CVE-2003-0062" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/02.10.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/02.10.03.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6803" source="BID">6803</ref>
      <ref url="http://www.iss.net/security_center/static/11282.php" source="XF" adv="1">nod32-pathname-bo(11282)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104490777824360&amp;w=2" source="BUGTRAQ">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0063" published="2003-03-03" name="CVE-2003-0063" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6940" source="BID">6940</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-067.html" source="REDHAT">RHSA-2003:067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-066.html" source="REDHAT">RHSA-2003:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-065.html" source="REDHAT">RHSA-2003:065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-064.html" source="REDHAT">RHSA-2003:064</ref>
      <ref url="http://www.debian.org/security/2003/dsa-380" source="DEBIAN">DSA-380</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0064" published="2003-03-03" name="CVE-2003-0064" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6942" source="BID">6942</ref>
      <ref url="http://www.securityfocus.com/advisories/6236" source="HP">HPSBUX0401-309</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.26" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.2" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0065" published="2003-03-03" name="CVE-2003-0065" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6945" source="BID">6945</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_university_of_singapore" name="uxterm">
        <vers num="2.3" />
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0066" published="2003-03-03" name="CVE-2003-0066" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6953" source="BID">6953</ref>
      <ref url="http://www.securityfocus.com/advisories/5137" source="GENTOO">200303-16</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-055.html" source="REDHAT">RHSA-2003:055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-054.html" source="REDHAT">RHSA-2003:054</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003" source="MANDRAKE">MDKSA-2003:003</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.7.5" />
        <vers num="2.7.6" />
        <vers num="2.7.7" />
        <vers num="2.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0067" published="2003-03-18" name="CVE-2003-0067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aterm" name="aterm">
        <vers num="0.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0068" published="2003-03-03" name="CVE-2003-0068" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/10237" source="BID">10237</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" source="MANDRAKE">MDKSA-2003:040</ref>
      <ref url="http://www.debian.org/security/2004/dsa-496" source="DEBIAN">DSA-496</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.8.10" />
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0069" published="2003-03-18" name="CVE-2003-0069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.osvdb.org/8347" source="OSVDB">8347</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers num="0.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0070" published="2003-03-03" name="CVE-2003-0070" modified="2010-08-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/77.html

'CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-053.html" source="REDHAT">RHSA-2003:053</ref>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://seclists.org/lists/bugtraq/2003/Mar/0010.html" source="GENTOO">GLSA-200303-2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnome-terminal">
        <vers num="2.0" />
        <vers num="2.2" />
      </prod>
      <prod vendor="nalin_dahyabhai" name="vte">
        <vers num="0.11.21" />
        <vers num="0.12.2" />
        <vers num="0.14.2" />
        <vers num="0.15.0" />
        <vers num="0.16.14" />
        <vers num="0.17.4" />
        <vers num="0.20.5" />
        <vers num="0.22.5" />
        <vers num="0.24.3" />
        <vers num="0.25.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0071" published="2003-03-03" name="CVE-2003-0071" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11415.php" source="XF" adv="1">terminal-emulator-dec-udk(11415)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6950" source="BID">6950</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-067.html" source="REDHAT">RHSA-2003:067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-066.html" source="REDHAT">RHSA-2003:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-065.html" source="REDHAT">RHSA-2003:065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-064.html" source="REDHAT">RHSA-2003:064</ref>
      <ref url="http://www.debian.org/security/2003/dsa-380" source="DEBIAN">DSA-380</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0072" published="2003-04-02" name="CVE-2003-0072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN" patch="1" adv="1">DSA-266</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.securityfocus.com/bid/7184" source="BID">7184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" source="SUNALERT">54042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0" />
        <vers num="1.2.2.beta1" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5_1.0.6" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0073" published="2003-02-19" name="CVE-2003-0073" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-303" source="DEBIAN" patch="1" adv="1">DSA-303</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385719107879&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://www.mysql.com/doc/en/News-3.23.55.html" source="CONFIRM" adv="1">http://www.mysql.com/doc/en/News-3.23.55.html</ref>
      <ref url="http://www.securityfocus.com/bid/6718" source="BID">6718</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-166.html" source="REDHAT">RHSA-2003:166</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-094.html" source="REDHAT">RHSA-2003:094</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-093.html" source="REDHAT">RHSA-2003:093</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013" source="MANDRAKE">MDKSA-2003:013</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html" source="ENGARDE">ESA-20030220-004</ref>
      <ref url="http://www.iss.net/security_center/static/11199.php" source="XF">mysql-mysqlchangeuser-doublefree-dos(11199)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" source="CONECTIVA">CLA-2003:743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:436" source="OVAL" sig="1">oval:org.mitre.oval:def:436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.31" />
        <vers num="3.23.36" />
        <vers num="3.23.41" />
        <vers num="3.23.47" />
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.54" />
        <vers num="3.23.54a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0074" published="2003-02-19" name="CVE-2003-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6715" source="BID" patch="1" adv="1">6715</ref>
      <ref url="http://www.iss.net/security_center/static/11193.php" source="XF">plptools-plpnsfd-format-string(11193)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386699725019&amp;w=2" source="BUGTRAQ" adv="1">20030129 Re: Local root vuln in SuSE 8.0 plptools package</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385772908969&amp;w=2" source="BUGTRAQ" adv="1">20030129 Local root vuln in SuSE 8.0 plptools package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plptools" name="plptools">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0075" published="2003-02-19" name="CVE-2003-0075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6745" source="BID" patch="1" adv="1">6745</ref>
      <ref url="http://www.pivx.com/luigi/adv/blade942-adv.txt" source="MISC" patch="1" adv="1">http://www.pivx.com/luigi/adv/blade942-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104446346127432&amp;w=2" source="GENTOO" patch="1">GLSA-200302-04</ref>
      <ref url="http://www.iss.net/security_center/static/11227.php" source="XF" adv="1">bladeenc-myfseek-code-execution(11227)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428700106672&amp;w=2" source="BUGTRAQ">20030202 Bladeenc 0.94.2 code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bladeenc" name="bladeenc">
        <vers num="0.92.7" />
        <vers num="0.93.10" />
        <vers num="0.94.0" />
        <vers num="0.94.1" />
        <vers num="0.94.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0076" published="2003-02-19" name="CVE-2003-0076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104437720116243&amp;w=2" source="BUGTRAQ" patch="1">20030204 GLSA:  qt-dcgui</ref>
      <ref url="http://www.iss.net/security_center/static/11246.php" source="XF" adv="1">qtdcgui-directory-download-files(11246)</ref>
      <ref url="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html" source="CONFIRM" adv="1">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcgui" name="dcgui">
        <vers num="0.2" />
        <vers num="0.2.1" />
      </prod>
      <prod vendor="qt-dcgui" name="qt-dcgui">
        <vers num="0.2" />
        <vers num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0077" published="2003-03-18" name="CVE-2003-0077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-071.html" source="REDHAT">RHSA-2003:071</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-070.html" source="REDHAT">RHSA-2003:070</ref>
      <ref url="http://www.osvdb.org/4917" source="OSVDB">4917</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hanterm" name="hanterm-xf">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0078" published="2003-03-03" name="CVE-2003-0078" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openssl.org/news/secadv_20030219.txt" source="CONFIRM" patch="1" adv="1">http://www.openssl.org/news/secadv_20030219.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104568426824439&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</ref>
      <ref url="http://www.iss.net/security_center/static/11369.php" source="XF" adv="1">ssl-cbc-information-leak(11369)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-253" source="DEBIAN" adv="1">DSA-253</ref>
      <ref url="http://www.trustix.org/errata/2003/0005" source="TRUSTIX">2003-0005</ref>
      <ref url="http://www.securityfocus.com/bid/6884" source="BID">6884</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-205.html" source="REDHAT">RHSA-2003:205</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-104.html" source="REDHAT">RHSA-2003:104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-082.html" source="REDHAT">RHSA-2003:082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-063.html" source="REDHAT">RHSA-2003:063</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-062.html" source="REDHAT">RHSA-2003:062</ref>
      <ref url="http://www.osvdb.org/3945" source="OSVDB">3945</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020" source="MANDRAKE">MDKSA-2003:020</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html" source="ENGARDE">ESA-20030220-005</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-051.shtml" source="CIAC">N-051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104577183206905&amp;w=2" source="GENTOO">GLSA-200302-10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567627211904&amp;w=2" source="BUGTRAQ">20030219 OpenSSL 0.9.7a and 0.9.6i released</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570" source="CONECTIVA">CLSA-2003:570</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" source="SGI">20030501-01-I</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc" source="NETBSD">NetBSD-SA2003-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.5a" />
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" edition="pre-release" />
        <vers num="5.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0079" published="2003-03-03" name="CVE-2003-0079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11415.php" source="XF" adv="1">terminal-emulator-dec-udk(11415)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6944" source="BID">6944</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-071.html" source="REDHAT">RHSA-2003:071</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-070.html" source="REDHAT">RHSA-2003:070</ref>
      <ref url="http://www.osvdb.org/4918" source="OSVDB">4918</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hanterm" name="hanterm-xf">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0080" published="2003-03-31" name="CVE-2003-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7128" source="BID" patch="1" adv="1">7128</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-072.html" source="REDHAT" patch="1" adv="1">RHSA-2003:072</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11552" source="XF" adv="1">gnomelokkit-forward-bypass-firewall(11552)</ref>
      <ref url="http://www.osvdb.org/4400" source="OSVDB">4400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnome-lokkit">
        <vers num="0.50_21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0081" published="2003-03-18" name="CVE-2003-0081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7049" source="BID" patch="1" adv="1">7049</ref>
      <ref url="http://www.guninski.com/etherre.html" source="MISC" patch="1" adv="1">http://www.guninski.com/etherre.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-258" source="DEBIAN" patch="1" adv="1">DSA-258</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11497" source="XF">ethereal-socks-format-string(11497)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-076.html" source="REDHAT">RHSA-2003:076</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" source="SUSE">SuSE-SA:2003:019</ref>
      <ref url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html" source="GENTOO">GLSA-200303-10</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html" source="FULLDISC">20030308 Ethereal format string bug, yet still ethereal much better than windows</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051" source="MANDRAKE">MDKSA-2003:051</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627" source="CONECTIVA">CLSA-2003:627</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:54" source="OVAL" sig="1">oval:org.mitre.oval:def:54</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.8.18" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0082" published="2003-04-02" name="CVE-2003-0082" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN" patch="1" adv="1">DSA-266</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.securityfocus.com/bid/7185" source="BID">7185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" source="SUNALERT">54042</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430" source="OVAL" sig="1">oval:org.mitre.oval:def:4430</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536" source="OVAL" sig="1">oval:org.mitre.oval:def:2536</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244" source="OVAL" sig="1">oval:org.mitre.oval:def:244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0" />
        <vers num="1.2.2.beta1" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5_1.0.6" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0083" published="2003-04-02" name="CVE-2003-0083" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-139.html" source="REDHAT" patch="1" adv="1">RHSA-2003:139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
      <ref url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH" source="CONFIRM">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</ref>
      <ref url="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25" source="CONFIRM" adv="1">http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25</ref>
      <ref url="http://secunia.com/advisories/8146" source="SECUNIA">8146</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024081011678&amp;w=2" source="BUGTRAQ">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:151" source="OVAL" sig="1">oval:org.mitre.oval:def:151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0084" published="2003-05-12" name="CVE-2003-0084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7448" source="BID" patch="1" adv="1">7448</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-114.html" source="REDHAT" patch="1" adv="1">RHSA-2003:114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11893" source="XF">modauthany-command-execution(11893)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-113.html" source="REDHAT">RHSA-2003:113</ref>
      <ref url="http://www.itlab.musc.edu/webNIS/mod_auth_any.html" source="CONFIRM">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-090.shtml" source="CIAC">N-090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_auth_any" name="mod_auth_any">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0085" published="2003-03-31" name="CVE-2003-0085" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/298233" source="CERT-VN">VU#298233</ref>
      <ref url="http://www.securityfocus.com/bid/7106" source="BID" patch="1" adv="1">7106</ref>
      <ref url="http://www.debian.org/security/2003/dsa-262" source="DEBIAN" patch="1" adv="1">DSA-262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792723017768&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 Security Bugfix for Samba - Samba 2.2.8 Released</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 GLSA:  samba (200303-11)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-003-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-095.html" source="REDHAT">RHSA-2003:095</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_016_samba.html" source="SUSE">SuSE-SA:2003:016</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" source="SGI">20030302-01-I</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-003-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-096.html" source="REDHAT">RHSA-2003:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" source="MANDRAKE">MDKSA-2003:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" source="GENTOO">GLSA-200303-11</ref>
      <ref url="http://secunia.com/advisories/8303" source="SECUNIA">8303</ref>
      <ref url="http://secunia.com/advisories/8299" source="SECUNIA">8299</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2" source="BUGTRAQ">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:552" source="OVAL" sig="1">oval:org.mitre.oval:def:552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="cifs-9000_server">
        <vers num="a.01.05" />
        <vers num="a.01.06" />
        <vers num="a.01.07" />
        <vers num="a.01.08" />
        <vers num="a.01.08.01" />
        <vers num="a.01.09" />
        <vers num="a.01.09.01" />
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.1a" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0086" published="2003-03-31" name="CVE-2003-0086" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7107" source="BID" patch="1" adv="1">7107</ref>
      <ref url="http://www.debian.org/security/2003/dsa-262" source="DEBIAN" patch="1" adv="1">DSA-262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 GLSA:  samba (200303-11)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-095.html" source="REDHAT">RHSA-2003:095</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_016_samba.html" source="SUSE">SuSE-SA:2003:016</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" source="SGI">20030302-01-I</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="APPLE">APPLE-SA-2003-03-24</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-096.html" source="REDHAT">RHSA-2003:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" source="MANDRAKE">MDKSA-2003:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" source="GENTOO">GLSA-200303-11</ref>
      <ref url="http://secunia.com/advisories/8303" source="SECUNIA">8303</ref>
      <ref url="http://secunia.com/advisories/8299" source="SECUNIA">8299</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2" source="BUGTRAQ">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554" source="OVAL" sig="1">oval:org.mitre.oval:def:554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.1a" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0087" published="2003-03-03" name="CVE-2003-0087" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/02.12.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/02.12.03.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11309" source="XF">aix-aixterm-libim-bo(11309)</ref>
      <ref url="http://www.securityfocus.com/bid/6840" source="BID">6840</ref>
      <ref url="http://www.osvdb.org/7996" source="OSVDB">7996</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only" source="AIXAPAR">IY40320</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only" source="AIXAPAR">IY40317</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only" source="AIXAPAR">IY40307</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508833214691&amp;w=2" source="BUGTRAQ">20030212 libIM.a buffer overflow vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508375107938&amp;w=2" source="BUGTRAQ">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html" source="VULNWATCH">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_language_support" name="libim">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0088" published="2003-03-03" name="CVE-2003-0088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a021403-1.txt" source="ATSTAKE" patch="1" adv="1">A021403-1</ref>
      <ref url="http://www.iss.net/security_center/static/11332.php" source="XF" adv="1">macos-trublueenvironment-gain-privileges(11332)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/bid/6859" source="BID">6859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0089" published="2003-12-15" name="CVE-2003-0089" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13623" source="XF" patch="1" adv="1">hp-sd-utilities-bo(13623)</ref>
      <ref url="http://www.securityfocus.com/bid/8986" source="BID" patch="1" adv="1">8986</ref>
      <ref url="http://www.securityfocus.com/advisories/6030" source="HP" patch="1" adv="1">HPSBUX0311-293</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106873965001431&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5466" source="OVAL">oval:org.mitre.oval:def:5466</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0038.html" source="VULNWATCH">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0090" reject="1" published="2003-12-15" name="CVE-2003-0090" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2000-0844.  Reason: This candidate is a duplicate of CVE-2000-0844.  Notes: All CVE users should reference CVE-2000-0844 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0091" published="2003-04-02" name="CVE-2003-0091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html" source="VULNWATCH" patch="1" adv="1">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316957/30/25250/threaded" source="BUGTRAQ">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/8713" source="OSVDB">8713</ref>
      <ref url="http://www.nsfocus.com/english/homepage/sa2003-02.htm" source="MISC">http://www.nsfocus.com/english/homepage/sa2003-02.htm</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-068.shtml" source="CIAC">N-068</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1" source="SUNALERT">52443</ref>
      <ref url="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt" source="MISC">http://packetstormsecurity.org/0304-advisories/sa2003-02.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4383" source="OVAL" sig="1">oval:org.mitre.oval:def:4383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0092" published="2003-04-02" name="CVE-2003-0092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html" source="VULNWATCH" patch="1" adv="1">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/7240" source="BID">7240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316948/30/25250/threaded" source="BUGTRAQ">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1" source="SUNALERT">52388</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1905" source="OVAL" sig="1">oval:org.mitre.oval:def:1905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0093" published="2003-03-03" name="CVE-2003-0093" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11324" source="XF">tcpdump-radius-decoder-dos(11324)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-214.html" source="REDHAT">RHSA-2003:214</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-033.html" source="REDHAT">RHSA-2003:033</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-032.html" source="REDHAT">RHSA-2003:032</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" source="MANDRAKE">MDKSA-2003:027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-261" source="DEBIAN">DSA-261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4" />
        <vers num="3.4a6" />
        <vers num="3.5" />
        <vers num="3.5.2" />
        <vers num="3.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0094" published="2003-03-03" name="CVE-2003-0094" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11318" source="XF" adv="1">utillinux-mcookie-cookie-predictable(11318)</ref>
      <ref url="http://www.securityfocus.com/bid/6855" source="BID">6855</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016" source="MANDRAKE">MDKSA-2003:016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="util-linux">
        <vers num="2.11n" />
        <vers num="2.11u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0095" published="2003-03-03" name="CVE-2003-0095" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/953746" source="CERT-VN">VU#953746</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-05.html" source="CERT" adv="1">CA-2003-05</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/6849" source="BID">6849</ref>
      <ref url="http://www.osvdb.org/6319" source="OSVDB">6319</ref>
      <ref url="http://www.iss.net/security_center/static/11328.php" source="XF" adv="1">oracle-username-bo(11328)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-046.shtml" source="CIAC">N-046</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549693426042&amp;w=2" source="BUGTRAQ" adv="1">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.0.6" />
        <vers num="9.2.1" />
        <vers num="9.2.2" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.7" />
        <vers num="8.1.7.1" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.1.2" />
        <vers num="9.0.1.3" />
        <vers num="9.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0096" published="2003-03-03" name="CVE-2003-0096" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/840666" source="CERT-VN" adv="1">VU#840666</ref>
      <ref url="http://www.kb.cert.org/vuls/id/743954" source="CERT-VN">VU#743954</ref>
      <ref url="http://www.kb.cert.org/vuls/id/663786" source="CERT-VN">VU#663786</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-05.html" source="CERT">CA-2003-05</ref>
      <ref url="http://www.securityfocus.com/bid/6850" source="BID">6850</ref>
      <ref url="http://www.securityfocus.com/bid/6848" source="BID">6848</ref>
      <ref url="http://www.securityfocus.com/bid/6847" source="BID">6847</ref>
      <ref url="http://www.nextgenss.com/advisories/ora-tzofstbo.txt" source="MISC">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt" source="MISC">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/ora-bfilebo.txt" source="MISC">http://www.nextgenss.com/advisories/ora-bfilebo.txt</ref>
      <ref url="http://www.iss.net/security_center/static/11327.php" source="XF" adv="1">oracle-totimestamptz-bo(11327)</ref>
      <ref url="http://www.iss.net/security_center/static/11326.php" source="XF">oracle-tzoffset-bo(11326)</ref>
      <ref url="http://www.iss.net/security_center/static/11325.php" source="XF">oracle-bfilename-directory-bo(11325)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-046.shtml" source="CIAC">N-046</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550346303295&amp;w=2" source="BUGTRAQ">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549782327321&amp;w=2" source="BUGTRAQ">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549743326864&amp;w=2" source="BUGTRAQ">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html" source="VULNWATCH">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html" source="VULNWATCH">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html" source="VULNWATCH">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.0.6" />
        <vers num="9.2.1" />
        <vers num="9.2.2" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.7" />
        <vers num="8.1.7.1" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.1.2" />
        <vers num="9.0.1.3" />
        <vers num="9.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0097" published="2003-03-03" name="CVE-2003-0097" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567042700840&amp;w=2" source="GENTOO" patch="1" adv="1">GLSA-200302-09</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550977011668&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</ref>
      <ref url="http://www.slackware.com/changelog/current.php?cpu=i386" source="CONFIRM">http://www.slackware.com/changelog/current.php?cpu=i386</ref>
      <ref url="http://www.iss.net/security_center/static/11343.php" source="XF" adv="1">php-cgi-sapi-access(11343)</ref>
      <ref url="http://www.securityfocus.com/bid/6875" source="BID">6875</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567137502557&amp;w=2" source="GENTOO">GLSA-200302-09.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0098" published="2003-03-03" name="CVE-2003-0098" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-277" source="DEBIAN" patch="1" adv="1">DSA-277</ref>
      <ref url="http://www.securityfocus.com/bid/7200" source="BID">7200</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" source="SUSE">SuSE-SA:2003:022</ref>
      <ref url="http://www.iss.net/security_center/static/11334.php" source="XF">apcupsd-logevent-format-string(11334)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137900" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
      <ref url="http://securitytracker.com/id?1006108" source="SECTRACK">1006108</ref>
      <ref url="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt" source="MISC">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</ref>
      <ref url="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6" source="CONFIRM" adv="1">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" source="CALDERA">CSSA-2003-015.0</ref>
      <ref url="http://www.securityfocus.com/bid/6828" source="BID">6828</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" source="MANDRAKE">MDKSA-2003:018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="apcupsd">
        <vers prev="1" num="3.10.4" />
        <vers prev="1" num="3.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0099" published="2003-03-03" name="CVE-2003-0099" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-277" source="DEBIAN" patch="1" adv="1">DSA-277</ref>
      <ref url="http://www.securityfocus.com/bid/7200" source="BID">7200</ref>
      <ref url="http://www.iss.net/security_center/static/11491.php" source="XF" adv="1">apcupsd-vsprintf-multiple-bo(11491)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137900" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137892" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=137892</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" source="SUSE">SuSE-SA:2003:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" source="MANDRAKE">MDKSA-2003:018</ref>
      <ref url="http://securitytracker.com/id?1006108" source="SECTRACK">1006108</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" source="CALDERA">CSSA-2003-015.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="apcupsd">
        <vers num="3.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0100" published="2003-03-03" name="CVE-2003-0100" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104587206702715&amp;w=2" source="BUGTRAQ" patch="1">20030221 Re: Cisco IOS OSPF exploit</ref>
      <ref url="http://www.iss.net/security_center/static/11373.php" source="XF" adv="1">cisco-ios-ospf-bo(11373)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104576100719090&amp;w=2" source="BUGTRAQ">20030220 Cisco IOS OSPF exploit</ref>
      <ref url="http://www.securityfocus.com/bid/6895" source="BID">6895</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.1" />
        <vers num="11.1(13)" />
        <vers num="11.1(13)aa" />
        <vers num="11.1(13)ca" />
        <vers num="11.1(13)ia" />
        <vers num="11.1(15)aa" />
        <vers num="11.1(15)ca" />
        <vers num="11.1(15)ia" />
        <vers num="11.1(16)aa" />
        <vers num="11.1(16)ia" />
        <vers num="11.1(17)cc" />
        <vers num="11.1(17)ct" />
        <vers num="11.1(20)aa4" />
        <vers num="11.1(24a)" />
        <vers num="11.1(24b)" />
        <vers num="11.1(28a)ct" />
        <vers num="11.1(28a)ia" />
        <vers num="11.1(36)ca2" />
        <vers num="11.1(36)cc2" />
        <vers num="11.1(36)cc4" />
        <vers num="11.1(7)aa" />
        <vers num="11.1(7)ca" />
        <vers num="11.1(9)ia" />
        <vers num="11.1aa" />
        <vers num="11.1ca" />
        <vers num="11.1cc" />
        <vers num="11.1ct" />
        <vers num="11.1ia" />
        <vers num="11.2" />
        <vers num="11.2(10)bc" />
        <vers num="11.2(11b)t2" />
        <vers num="11.2(17)" />
        <vers num="11.2(19)gs0.2" />
        <vers num="11.2(19a)gs6" />
        <vers num="11.2(23a)bc1" />
        <vers num="11.2(26)p2" />
        <vers num="11.2(26a)" />
        <vers num="11.2(26b)" />
        <vers num="11.2(4)" />
        <vers num="11.2(4)f" />
        <vers num="11.2(4)f1" />
        <vers num="11.2(4)xa" />
        <vers num="11.2(4)xaf" />
        <vers num="11.2(8)p" />
        <vers num="11.2(8)sa1" />
        <vers num="11.2(8)sa3" />
        <vers num="11.2(8)sa5" />
        <vers num="11.2(8.9)sa6" />
        <vers num="11.2(9)p" />
        <vers num="11.2(9)xa" />
        <vers num="11.2bc" />
        <vers num="11.2f" />
        <vers num="11.2gs" />
        <vers num="11.2p" />
        <vers num="11.2sa" />
        <vers num="11.2wa3" />
        <vers num="11.2wa4" />
        <vers num="11.2xa" />
        <vers num="11.3" />
        <vers num="11.3(1)ed" />
        <vers num="11.3(1)t" />
        <vers num="11.3(11)b" />
        <vers num="11.3(11b)" />
        <vers num="11.3(11b)t2" />
        <vers num="11.3(11c)" />
        <vers num="11.3(2)xa" />
        <vers num="11.3(7)db1" />
        <vers num="11.3(8)db2" />
        <vers num="11.3aa" />
        <vers num="11.3da" />
        <vers num="11.3db" />
        <vers num="11.3ha" />
        <vers num="11.3ma" />
        <vers num="11.3na" />
        <vers num="11.3t" />
        <vers num="11.3wa4" />
        <vers num="11.3xa" />
        <vers num="12.0" />
        <vers num="12.0(1)" />
        <vers num="12.0(1)w" />
        <vers num="12.0(1)xa3" />
        <vers num="12.0(1)xb" />
        <vers num="12.0(1)xe" />
        <vers num="12.0(10)s7" />
        <vers num="12.0(10)w5" />
        <vers num="12.0(10)w5(18f)" />
        <vers num="12.0(10)w5(18g)" />
        <vers num="12.0(10a)" />
        <vers num="12.0(11)s6" />
        <vers num="12.0(11)st4" />
        <vers num="12.0(11a)" />
        <vers num="12.0(12)s3" />
        <vers num="12.0(12a)" />
        <vers num="12.0(13)s6" />
        <vers num="12.0(13)w5(19c)" />
        <vers num="12.0(13)wt6(1)" />
        <vers num="12.0(13a)" />
        <vers num="12.0(14)s7" />
        <vers num="12.0(14)st" />
        <vers num="12.0(14)st3" />
        <vers num="12.0(14)w5(20)" />
        <vers num="12.0(14a)" />
        <vers num="12.0(15)s3" />
        <vers num="12.0(15)s6" />
        <vers num="12.0(15a)" />
        <vers num="12.0(16)s8" />
        <vers num="12.0(16)sc3" />
        <vers num="12.0(16)st1" />
        <vers num="12.0(16)w5(21)" />
        <vers num="12.0(16.06)s" />
        <vers num="12.0(16a)" />
        <vers num="12.0(17)" />
        <vers num="12.0(17)s" />
        <vers num="12.0(17)s4" />
        <vers num="12.0(17)sl2" />
        <vers num="12.0(17)sl6" />
        <vers num="12.0(17)st1" />
        <vers num="12.0(17)st5" />
        <vers num="12.0(17a)" />
        <vers num="12.0(18)s" />
        <vers num="12.0(18)s5" />
        <vers num="12.0(18)st1" />
        <vers num="12.0(18)w5(22b)" />
        <vers num="12.0(18b)" />
        <vers num="12.0(2)" />
        <vers num="12.0(2)xc" />
        <vers num="12.0(2)xd" />
        <vers num="12.0(2)xe" />
        <vers num="12.0(2)xf" />
        <vers num="12.0(2)xg" />
        <vers num="12.0(2b)" />
        <vers num="12.0(3)" />
        <vers num="12.0(3)t2" />
        <vers num="12.0(3d)" />
        <vers num="12.0(4)s" />
        <vers num="12.0(4)t" />
        <vers num="12.0(4)xe" />
        <vers num="12.0(4)xe1" />
        <vers num="12.0(4)xm" />
        <vers num="12.0(4)xm1" />
        <vers num="12.0(5)t" />
        <vers num="12.0(5)t1" />
        <vers num="12.0(5)wc" />
        <vers num="12.0(5)wc2" />
        <vers num="12.0(5)wc2b" />
        <vers num="12.0(5)wc3" />
        <vers num="12.0(5)wc3b" />
        <vers num="12.0(5)wx" />
        <vers num="12.0(5)xe" />
        <vers num="12.0(5)xk" />
        <vers num="12.0(5)xk2" />
        <vers num="12.0(5)xn" />
        <vers num="12.0(5)xn1" />
        <vers num="12.0(5)xs" />
        <vers num="12.0(5)xu" />
        <vers num="12.0(5)yb4" />
        <vers num="12.0(5.1)xp" />
        <vers num="12.0(5.2)xu" />
        <vers num="12.0(5.3)wc1" />
        <vers num="12.0(5.4)wc1" />
        <vers num="12.0(6b)" />
        <vers num="12.0(7)db2" />
        <vers num="12.0(7)dc1" />
        <vers num="12.0(7)s1" />
        <vers num="12.0(7)sc" />
        <vers num="12.0(7)t" />
        <vers num="12.0(7)t2" />
        <vers num="12.0(7)wx5(15a)" />
        <vers num="12.0(7)xe" />
        <vers num="12.0(7)xe2" />
        <vers num="12.0(7)xf" />
        <vers num="12.0(7)xf1" />
        <vers num="12.0(7)xk" />
        <vers num="12.0(7)xk3" />
        <vers num="12.0(7)xv" />
        <vers num="12.0(7.4)s" />
        <vers num="12.0(7a)" />
        <vers num="12.0(8)" />
        <vers num="12.0(8)s1" />
        <vers num="12.0(8.0.2)s" />
        <vers num="12.0(8.3)sc" />
        <vers num="12.0(8a)" />
        <vers num="12.0(9)" />
        <vers num="12.0(9)s" />
        <vers num="12.0(9)s8" />
        <vers num="12.0(9a)" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0t" />
        <vers num="12.0w5" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0wx" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xp" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xu" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0101" published="2003-03-03" name="CVE-2003-0101" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2" source="CONFIRM" patch="1">http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610300325629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</ref>
      <ref url="http://www.securityfocus.com/bid/6915" source="BID">6915</ref>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/62_e.html" source="MISC">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</ref>
      <ref url="http://www.iss.net/security_center/static/11390.php" source="XF" adv="1">webmin-usermin-root-access(11390)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-319" source="DEBIAN">DSA-319</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-058.shtml" source="CIAC">N-058</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610336226274&amp;w=2" source="BUGTRAQ">20030224 GLSA:  usermin (200302-14)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610245624895&amp;w=2" source="BUGTRAQ">20030224 Webmin 1.050 - 1.060 remote exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html" source="ENGARDE">ESA-20030225-006</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html" source="HP">HPSBUX0303-250</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I" source="SGI">20030602-01-I</ref>
      <ref url="http://www.securitytracker.com/id?1006160" source="SECTRACK">1006160</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025" source="MANDRAKE">MDKSA-2003:025</ref>
      <ref url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html" source="CONFIRM">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</ref>
      <ref url="http://secunia.com/advisories/8163" source="SECUNIA">8163</ref>
      <ref url="http://secunia.com/advisories/8115" source="SECUNIA">8115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="engardelinux" name="guardian_digital_webtool">
        <vers num="1.2" />
      </prod>
      <prod vendor="usermin" name="usermin">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers num="0.98" />
        <vers num="0.99" />
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="1.0.50" />
        <vers num="1.0.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0102" published="2003-03-18" name="CVE-2003-0102" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/611865" source="CERT-VN">VU#611865</ref>
      <ref url="http://www.securityfocus.com/bid/7008" source="BID" patch="1" adv="1">7008</ref>
      <ref url="http://www.idefense.com/advisory/03.04.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/03.04.03.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11469" source="XF">file-afctr-read-bo(11469)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-087.html" source="REDHAT">RHSA-2003:087</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-086.html" source="REDHAT">RHSA-2003:086</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_017_file.html" source="SUSE">SuSE-SA:2003:017</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030" source="MANDRAKE">MDKSA-2003:030</ref>
      <ref url="http://www.debian.org/security/2003/dsa-260" source="DEBIAN">DSA-260</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104680706201721&amp;w=2" source="BUGTRAQ">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</ref>
      <ref url="http://lwn.net/Alerts/34908/" source="IMMUNIX">IMNX-2003-7+-012-01</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc" source="NETBSD">NetBSD-SA2003-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="file" name="file">
        <vers num="3.28" />
        <vers num="3.30" />
        <vers num="3.32" />
        <vers num="3.33" />
        <vers num="3.34" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="3.37" />
        <vers num="3.39" />
        <vers num="3.40" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0103" published="2003-03-07" name="CVE-2003-0103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6952" source="BID" adv="1">6952</ref>
      <ref url="http://www.iss.net/security_center/static/11421.php" source="XF">nokia-6210-vcard-dos(11421)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="6210_handset">
        <vers num="5.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0104" published="2003-03-18" name="CVE-2003-0104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7053" source="BID" patch="1" adv="1">7053</ref>
      <ref url="http://www.iss.net/security_center/static/10962.php" source="XF" patch="1" adv="1">peoplesoft-schedulertransfer-create-files(10962)</ref>
      <ref url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999" source="ISS" patch="1" adv="1">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.10" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="8.15" />
        <vers num="8.16" />
        <vers num="8.17" />
        <vers num="8.18" />
        <vers num="8.40" />
        <vers num="8.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0105" published="2004-09-28" name="CVE-2003-0105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16947" source="XF" adv="1">servermask-header-obtain-info(16947)</ref>
      <ref url="http://www.corsaire.com/advisories/c030224-001.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c030224-001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215441332682&amp;w=2" source="BUGTRAQ">20040810 Corsaire Security Advisory - Port80 Software ServerMask inconsistencies</ref>
    </refs>
    <vuln_soft>
      <prod vendor="port80_software" name="servermask">
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0106" published="2003-04-02" name="CVE-2003-0106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754" source="CONFIRM" patch="1" adv="1">http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869513822233&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref url="http://www.securityfocus.com/bid/7196" source="BID" adv="1">7196</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html" source="VULNWATCH">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104868285106289&amp;w=2" source="NTBUGTRAQ">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0107" published="2003-03-07" name="CVE-2003-0107" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/142121" source="CERT-VN">VU#142121</ref>
      <ref url="http://www.iss.net/security_center/static/11381.php" source="XF" adv="1">zlib-gzprintf-bo(11381)</ref>
      <ref url="http://online.securityfocus.com/archive/1/312869" source="BUGTRAQ">20030222 buffer overrun in zlib 1.1.4</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610337726297&amp;w=2" source="BUGTRAQ">20030223 poc zlib sploit just for fun :)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref url="http://www.securityfocus.com/bid/6913" source="BID">6913</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-081.html" source="REDHAT">RHSA-2003:081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-079.html" source="REDHAT">RHSA-2003:079</ref>
      <ref url="http://www.osvdb.org/6599" source="OSVDB">6599</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033" source="MANDRAKE">MDKSA-2003:033</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405" source="SUNALERT">57405</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887247624907&amp;w=2" source="GENTOO">GLSA-200303-25</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104620610427210&amp;w=2" source="BUGTRAQ">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610536129508&amp;w=2" source="BUGTRAQ">20030224 Re: buffer overrun in zlib 1.1.4</ref>
      <ref url="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619" source="CONECTIVA">CLSA-2003:619</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc" source="NETBSD">NetBSD-SA2003-004</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt" source="CALDERA">CSSA-2003-011.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zlib">
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0108" published="2003-03-07" name="CVE-2003-0108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6974" source="BID" patch="1" adv="1">6974</ref>
      <ref url="http://www.idefense.com/advisory/02.27.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/02.27.03.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-255" source="DEBIAN" patch="1" adv="1">DSA-255</ref>
      <ref url="http://www.iss.net/security_center/static/11434.php" source="XF" adv="1">tcpdump-isakmp-dos(11434)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-214.html" source="REDHAT">RHSA-2003:214</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-085.html" source="REDHAT">RHSA-2003:085</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-032.html" source="REDHAT">RHSA-2003:032</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html" source="SUSE">SuSE-SA:2003:0015</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" source="MANDRAKE">MDKSA-2003:027</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104678787109030&amp;w=2" source="BUGTRAQ">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104637420104189&amp;w=2" source="BUGTRAQ">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629" source="CONECTIVA">CLA-2003:629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.5.2" />
        <vers num="3.6.2" />
        <vers num="3.7" />
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0109" published="2003-03-31" name="CVE-2003-0109" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-09.html" source="CERT" patch="1" adv="1">CA-2003-09</ref>
      <ref url="http://www.kb.cert.org/vuls/id/117394" source="CERT-VN">VU#117394</ref>
      <ref url="http://www.securityfocus.com/bid/7116" source="BID" patch="1" adv="1">7116</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-007.asp" source="MS" patch="1" adv="1">MS03-007</ref>
      <ref url="http://www.iss.net/security_center/static/11533.php" source="XF" patch="1" adv="1">http-webdav-long-request(11533)</ref>
      <ref url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029" source="ISS" patch="1" adv="1">20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability</ref>
      <ref url="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf" source="MISC">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q815021" source="MSKB">Q815021</ref>
      <ref url="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en" source="CONFIRM">http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104826785731151&amp;w=2" source="NTBUGTRAQ">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105768156625699&amp;w=2" source="BUGTRAQ">20030708 WDAV exploit without netcat and with pretty magic number</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887148323552&amp;w=2" source="BUGTRAQ">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869293619064&amp;w=2" source="BUGTRAQ">20030326 WebDAV exploit: using wide character decoder scheme</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861839130254&amp;w=2" source="BUGTRAQ">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826476427372&amp;w=2" source="BUGTRAQ">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:109" source="OVAL" sig="1">oval:org.mitre.oval:def:109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0110" published="2003-05-05" name="CVE-2003-0110" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-012.asp" source="MS" patch="1" adv="1">MS03-012</ref>
      <ref url="http://www.idefense.com/advisory/04.09.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/04.09.03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994487012027&amp;w=2" source="BUGTRAQ">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000 </ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:406" source="OVAL" sig="1">oval:org.mitre.oval:def:406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="fp1" />
        <vers num="2000" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="proxy_server">
        <vers num="2.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0111" published="2003-05-05" name="CVE-2003-0111" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/447569" source="CERT-VN" patch="1" adv="1">VU#447569</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-011.asp" source="MS" patch="1" adv="1">MS03-011</ref>
      <ref url="http://www.iss.net/security_center/static/11751.php" source="XF" patch="1" adv="1">msvm-bytecode-improper-validation(11751)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:136" source="OVAL" sig="1">oval:org.mitre.oval:def:136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_machine">
        <vers num="3802" />
        <vers num="3805" />
        <vers num="3809" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0112" published="2003-05-12" name="CVE-2003-0112" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/446338" source="CERT-VN">VU#446338</ref>
      <ref url="http://www.securityfocus.com/bid/7370" source="BID" patch="1" adv="1">7370</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-013.asp" source="MS" patch="1" adv="1">MS03-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11803" source="XF">win-kernel-lpcrequestwaitreplyport-bo(11803)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:779" source="OVAL" sig="1">oval:org.mitre.oval:def:779</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3145" source="OVAL" sig="1">oval:org.mitre.oval:def:3145</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:262" source="OVAL" sig="1">oval:org.mitre.oval:def:262</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2265" source="OVAL" sig="1">oval:org.mitre.oval:def:2265</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2022" source="OVAL" sig="1">oval:org.mitre.oval:def:2022</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:142" source="OVAL" sig="1">oval:org.mitre.oval:def:142</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1264" source="OVAL" sig="1">oval:org.mitre.oval:def:1264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0113" published="2003-05-12" name="CVE-2003-0113" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/169753" source="CERT-VN">VU#169753</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105138417416900&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030426 Buffer overflow in Internet Explorer's HTTP parsing code</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718285107246&amp;w=2" source="BUGTRAQ">20030701 URLMON.DLL buffer overflow - technical details</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:926" source="OVAL" sig="1">oval:org.mitre.oval:def:926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0114" published="2003-05-12" name="CVE-2003-0114" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104429340817718&amp;w=2" source="BUGTRAQ" adv="1">20030203 internet explorer local file reading</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:963" source="OVAL" sig="1">oval:org.mitre.oval:def:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0115" published="2003-05-12" name="CVE-2003-0115" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://www.iss.net/security_center/static/11848.php" source="XF" adv="1">ie-improper-thirdparty-rendering(11848)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0116" published="2003-05-12" name="CVE-2003-0116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/244729" source="CERT-VN">VU#244729</ref>
      <ref url="http://www.securityfocus.com/bid/6306" source="BID" patch="1" adv="1">6306</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://www.securityfocus.com/archive/1/301945" source="BUGTRAQ">20021203 Poisonous Style for Dialog window turns the zone off.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0117" published="2003-05-12" name="CVE-2003-0117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" source="MS" patch="1" adv="1">MS03-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216866132289&amp;w=2" source="BUGTRAQ">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":enterprise" />
        <vers num="2002" edition=":developer" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0118" published="2003-05-12" name="CVE-2003-0118" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" source="MS" patch="1" adv="1">MS03-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216839231951&amp;w=2" source="BUGTRAQ">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":standard" />
        <vers num="2000" edition=":developer" />
        <vers num="2000" edition=":enterprise" />
        <vers num="2000" edition="sp1a" />
        <vers num="2000" edition="sp1a:developer" />
        <vers num="2000" edition="sp1a:enterprise" />
        <vers num="2000" edition="sp1a:standard" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp2:standard" />
        <vers num="2000" edition="sp2:enterprise" />
        <vers num="2000" edition="sp2:developer" />
        <vers num="2002" edition="" />
        <vers num="2002" edition=":enterprise" />
        <vers num="2002" edition=":developer" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0119" published="2004-02-03" name="CVE-2003-0119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/624713" source="CERT-VN" patch="1" adv="1">VU#624713</ref>
      <ref url="http://www.securityfocus.com/bid/7264" source="BID" patch="1" adv="1">7264</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/4699c03b46f2d4f68525678c006d45ae/85256a3400529a8685256cde0008ddde?OpenDocument" source="IBM">MSS-OAR-E01-2003:0245.1</ref>
      <ref url="http://secunia.com/advisories/8221" source="SECUNIA">8221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0120" published="2003-03-07" name="CVE-2003-0120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-256" source="DEBIAN" patch="1" adv="1">DSA-256</ref>
      <ref url="http://www.securityfocus.com/bid/6978" source="BID">6978</ref>
      <ref url="http://www.iss.net/security_center/static/11439.php" source="XF">mhc-adb2mhc-insecure-tmp(11439)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhc-utils" name="mhc-utils">
        <vers num="0.25_snap2001-06-25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0121" published="2003-03-18" name="CVE-2003-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7044" source="BID" patch="1" adv="1">7044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716030503607&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/316311" source="BUGTRAQ">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0122" published="2003-03-18" name="CVE-2003-0122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/433489" source="CERT-VN">VU#433489</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/7037" source="BID" patch="1" adv="1">7037</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757319829443&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0010.html" source="MISC">http://www.rapid7.com/advisories/R7-0010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11526" source="XF">lotus-nrpc-bo(11526)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html" source="VULNWATCH">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="4.6.1" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" edition="" />
        <vers num="5.0.4" edition=":solaris" />
        <vers num="5.0.4a" />
        <vers num="5.0.5" edition="" />
        <vers num="5.0.5" edition=":" />
        <vers num="5.0.5" edition="::french" />
        <vers num="5.0.6" />
        <vers num="5.0.6a" />
        <vers num="5.0.7" edition="" />
        <vers num="5.0.7" edition=":solaris" />
        <vers num="5.0.7a" />
        <vers num="5.0.8" edition="" />
        <vers num="5.0.8" edition=":" />
        <vers num="5.0.8" edition="::french" />
        <vers num="5.0.8a" />
        <vers num="5.0.9" />
        <vers num="5.0.9a" />
      </prod>
      <prod vendor="ibm" name="lotus_notes_client">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.9a" />
        <vers num="r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0123" published="2003-03-18" name="CVE-2003-0123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/411489" source="CERT-VN">VU#411489</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/7038" source="BID" patch="1" adv="1">7038</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757545500368&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0011.html" source="MISC">http://www.rapid7.com/advisories/R7-0011.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11525" source="XF">lotus-web-retriever-bo(11525)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="4.6.1" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" edition="" />
        <vers num="5.0.4" edition=":solaris" />
        <vers num="5.0.4a" />
        <vers num="5.0.5" edition="" />
        <vers num="5.0.5" edition=":" />
        <vers num="5.0.5" edition="::french" />
        <vers num="5.0.6" />
        <vers num="5.0.6a" />
        <vers num="5.0.7" edition="" />
        <vers num="5.0.7" edition=":solaris" />
        <vers num="5.0.7a" />
        <vers num="5.0.8" edition="" />
        <vers num="5.0.8" edition=":" />
        <vers num="5.0.8" edition="::french" />
        <vers num="5.0.8a" />
        <vers num="5.0.9" />
        <vers num="5.0.9a" />
      </prod>
      <prod vendor="ibm" name="lotus_notes_client">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.9a" />
        <vers num="r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0124" published="2003-03-18" name="CVE-2003-0124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7066" source="BID" patch="1" adv="1">7066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104740927915154&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030311 Vulnerability in man &lt; 1.5l</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11512" source="XF">man-myxsprintf-code-execution(11512)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-134.html" source="REDHAT">RHSA-2003:134</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-133.html" source="REDHAT">RHSA-2003:133</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285112752&amp;w=2" source="GENTOO">GLSA-200303-13</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620" source="CONECTIVA">CLSA-2003:620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="man">
        <vers num="1.5h1" />
        <vers num="1.5i" />
        <vers num="1.5i2" />
        <vers num="1.5j" />
        <vers num="1.5k" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0125" published="2003-03-18" name="CVE-2003-0125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" source="MISC" patch="1" adv="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
      <ref url="ftp://ftp.multitech.com/Routers/RF550VPN.TXT" source="CONFIRM" adv="1">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11514" source="XF">routefinder-vpn-options-bo(11514)</ref>
      <ref url="http://www.securityfocus.com/bid/7067" source="BID">7067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="multitech" name="routefinder_550_vpn">
        <vers prev="1" num="4.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0126" published="2003-03-18" name="CVE-2003-0126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" source="MISC" patch="1" adv="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="multitech" name="routefinder_550_vpn">
        <vers prev="1" num="4.63" />
        <vers num="4.64_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0127" published="2003-03-31" name="CVE-2003-0127" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/628849" source="CERT-VN" adv="1">VU#628849</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-098.html" source="REDHAT" patch="1" adv="1">RHSA-2003:098</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-145.html" source="REDHAT">RHSA-2003:145</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN">DSA-423</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN">DSA-311</ref>
      <ref url="http://www.debian.org/security/2003/dsa-276" source="DEBIAN">DSA-276</ref>
      <ref url="http://www.debian.org/security/2003/dsa-270" source="DEBIAN">DSA-270</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200303-17.xml" source="GENTOO">GLSA-200303-17</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-088.html" source="REDHAT">RHSA-2003:088</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt" source="CALDERA">CSSA-2003-020.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-103.html" source="REDHAT">RHSA-2003:103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039" source="MANDRAKE">MDKSA-2003:039</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038" source="MANDRAKE">MDKSA-2003:038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" source="ENGARDE">ESA-20030515-017</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html" source="VULNWATCH">20030317 Fwd: Ptrace hole / Linux 2.2.25</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:254" source="OVAL" sig="1">oval:org.mitre.oval:def:254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" />
        <vers num="2.2.16" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0128" published="2003-03-24" name="CVE-2003-0128" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7117" source="BID" patch="1" adv="1">7117</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-108.html" source="REDHAT">RHSA-2003:108</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" source="BUGTRAQ">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" source="MANDRAKE">MDKSA-2003:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" source="GENTOO">GLSA-200303-18</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" source="BUGTRAQ">20030321 GLSA:  evolution (200303-18)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" source="CONECTIVA">CLA-2003:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:107" source="OVAL" sig="1">oval:org.mitre.oval:def:107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0129" published="2003-03-24" name="CVE-2003-0129" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7118" source="BID" patch="1" adv="1">7118</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030321 GLSA:  evolution (200303-18)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-108.html" source="REDHAT">RHSA-2003:108</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" source="BUGTRAQ">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" source="MANDRAKE">MDKSA-2003:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" source="GENTOO">GLSA-200303-18</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" source="CONECTIVA">CLA-2003:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:108" source="OVAL" sig="1">oval:org.mitre.oval:def:108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0130" published="2003-03-24" name="CVE-2003-0130" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7119" source="BID" patch="1" adv="1">7119</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030321 GLSA:  evolution (200303-18)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-108.html" source="REDHAT">RHSA-2003:108</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" source="BUGTRAQ">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" source="MANDRAKE">MDKSA-2003:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" source="GENTOO">GLSA-200303-18</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" source="CONECTIVA">CLA-2003:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:111" source="OVAL" sig="1">oval:org.mitre.oval:def:111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0131" published="2003-03-24" name="CVE-2003-0131" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/888801" source="CERT-VN" adv="1">VU#888801</ref>
      <ref url="http://www.securityfocus.com/bid/7148" source="BID" patch="1" adv="1">7148</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811162730834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11586" source="XF" adv="1">ssl-premaster-information-leak(11586)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="BUGTRAQ">20030327 Immunix Secured OS 7+ openssl update</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-102.html" source="REDHAT">RHSA-2003:102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-101.html" source="REDHAT">RHSA-2003:101</ref>
      <ref url="http://www.openssl.org/news/secadv_20030319.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20030319.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_024_openssl.html" source="SUSE">SuSE-SA:2003:024</ref>
      <ref url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" source="MISC">http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html</ref>
      <ref url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" source="IMMUNIX">IMNX-2003-7+-001-01</ref>
      <ref url="http://www.debian.org/security/2003/dsa-288" source="DEBIAN">DSA-288</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref url="http://eprint.iacr.org/2003/052/" source="MISC" adv="1">http://eprint.iacr.org/2003/052/</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" source="SGI">20030501-01-I</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc" source="NETBSD">NetBSD-SA2003-007</ref>
      <ref url="http://www.suse.de/de/security/2003_024_openssl.html" source="SUSE">SuSE-SA:2003:024</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="BUGTRAQ">20030327 Immunix Secured OS 7+ openssl update</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html" source="OPENPKG">OpenPKG-SA-2003.026</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035" source="MANDRAKE">MDKSA-2003:035</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml" source="GENTOO">GLSA-200303-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878215721135&amp;w=2" source="TRUSTIX">2003-0013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852637112330&amp;w=2" source="BUGTRAQ">20030324 GLSA:  openssl (200303-20)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" source="CONECTIVA">CLA-2003:625</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" source="CALDERA">CSSA-2003-014.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:461" source="OVAL" sig="1">oval:org.mitre.oval:def:461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.7" />
        <vers num="0.9.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0132" published="2003-04-11" name="CVE-2003-0132" modified="2009-05-13" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/206537" source="CERT-VN">VU#206537</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1233" source="VUPEN">ADV-2009-1233</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-139.html" source="REDHAT">RHSA-2003:139</ref>
      <ref url="http://www.idefense.com/advisory/04.08.03.txt" source="MISC">http://www.idefense.com/advisory/04.08.03.txt</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147" source="MISC">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</ref>
      <ref url="http://secunia.com/advisories/8499" source="SECUNIA">8499</ref>
      <ref url="http://secunia.com/advisories/34920" source="SECUNIA">34920</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013378320711&amp;w=2" source="BUGTRAQ">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001663120995&amp;w=2" source="BUGTRAQ">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994309010974&amp;w=2" source="BUGTRAQ">20030408 Exploit Code Released for Apache 2.x Memory Leak</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994239010517&amp;w=2" source="BUGTRAQ">20030409 GLSA:  apache (200304-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104982175321731&amp;w=2" source="BUGTRAQ">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156" source="OVAL" sig="1">oval:org.mitre.oval:def:156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0133" published="2003-05-05" name="CVE-2003-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-126.html" source="REDHAT" patch="1" adv="1">RHSA-2003:126</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046" source="MANDRAKE">MDKSA-2003:046</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" source="CONECTIVA">CLA-2003:737</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:138" source="OVAL" sig="1">oval:org.mitre.oval:def:138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gtkhtml">
        <vers num="1.1.10" />
        <vers num="1.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0134" published="2003-04-11" name="CVE-2003-0134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
      <ref url="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35" source="CONFIRM" patch="1">http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" source="BUGTRAQ">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0135" published="2003-04-11" name="CVE-2003-0135" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7253" source="BID" patch="1" adv="1">7253</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-084.html" source="REDHAT" patch="1" adv="1">RHSA-2003:084</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:634" source="OVAL" sig="1">oval:org.mitre.oval:def:634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0136" published="2003-05-05" name="CVE-2003-0136" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-142.html" source="REDHAT" patch="1" adv="1">RHSA-2003:142</ref>
      <ref url="http://www.debian.org/security/2003/dsa-285" source="DEBIAN" patch="1" adv="1">DSA-285</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:423" source="OVAL" sig="1">oval:org.mitre.oval:def:423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astart_technologies" name="lprng">
        <vers num="3.7.4" />
        <vers num="3.8.10.1" />
        <vers num="3.8.19" />
        <vers num="3.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0137" published="2003-03-18" name="CVE-2003-0137" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a031303-2.txt" source="ATSTAKE" adv="1">A031303-2</ref>
      <ref url="http://secunia.com/advisories/8301" source="SECUNIA">8301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="sgsn_dx200">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0138" published="2003-03-24" name="CVE-2003-0138" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/623217" source="CERT-VN" patch="1" adv="1">VU#623217</ref>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN" patch="1" adv="1">DSA-266</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.debian.org/security/2003/dsa-273" source="DEBIAN">DSA-273</ref>
      <ref url="http://www.debian.org/security/2003/dsa-269" source="DEBIAN">DSA-269</ref>
      <ref url="http://www.securityfocus.com/bid/7113" source="BID">7113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" source="BUGTRAQ">20030317 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 protocol</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:248" source="OVAL" sig="1">oval:org.mitre.oval:def:248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0139" published="2003-03-24" name="CVE-2003-0139" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/442569" source="CERT-VN" patch="1" adv="1">VU#442569</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.debian.org/security/2003/dsa-273" source="DEBIAN">DSA-273</ref>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN">DSA-266</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317130/30/25250/threaded" source="BUGTRAQ">20030330 GLSA: openafs (200303-26)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:250" source="OVAL" sig="1">oval:org.mitre.oval:def:250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0140" published="2003-03-24" name="CVE-2003-0140" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7120" source="BID" patch="1" adv="1">7120</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104818814931378&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11583" source="XF" adv="1">mutt-folder-name-bo(11583)</ref>
      <ref url="http://www.securityfocus.com/archive/1/315679" source="BUGTRAQ" adv="1">20030319 mutt-1.4.1 fixes a buffer overflow.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-109.html" source="REDHAT">RHSA-2003:109</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_020_mutt.html" source="SUSE">SuSE-SA:2003:020</ref>
      <ref url="http://www.debian.org/security/2003/dsa-268" source="DEBIAN">DSA-268</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041" source="MANDRAKE">MDKSA-2003:041</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml" source="GENTOO">GLSA-200303-19</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105171507629573&amp;w=2" source="BUGTRAQ">20030430 GLSA:  balsa (200304-10)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852190605988&amp;w=2" source="BUGTRAQ">20030322 GLSA:  mutt (200303-19)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104817995421439&amp;w=2" source="BUGTRAQ">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630" source="CONECTIVA">CLA-2003:630</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626" source="CONECTIVA">CLA-2003:626</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:434" source="OVAL" sig="1">oval:org.mitre.oval:def:434</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2" source="OVAL" sig="1">oval:org.mitre.oval:def:2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.3.12" />
        <vers num="1.3.16" />
        <vers num="1.3.17" />
        <vers num="1.3.22" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.27" />
        <vers num="1.4.0" />
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0141" published="2003-04-02" name="CVE-2003-0141" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/705761" source="CERT-VN" adv="1">VU#705761</ref>
      <ref url="http://www.securityfocus.com/bid/7177" source="BID" patch="1" adv="1">7177</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887465427579&amp;w=2" source="BUGTRAQ">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html" source="VULNWATCH">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="2.0" />
        <vers num="6.0.10.505" edition="gold" />
        <vers num="6.0.11.818" />
        <vers num="6.0.11.830" />
        <vers num="6.0.11.841" />
        <vers num="6.0.11.853" />
        <vers num="9.0.0.288" />
        <vers num="9.0.0.297" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0142" published="2003-08-18" name="CVE-2003-0142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/689835" source="CERT-VN">VU#689835</ref>
      <ref url="http://www.securityfocus.com/archive/1/328224" source="BUGTRAQ" adv="1">20030708 Adobe Acrobat and PDF security: no improvements for 2 years</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0143" published="2003-03-18" name="CVE-2003-0143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7058" source="BID" patch="1" adv="1">7058</ref>
      <ref url="http://www.debian.org/security/2003/dsa-259" source="DEBIAN" patch="1" adv="1">DSA-259</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11516" source="XF" adv="1">qpopper-popmsg-macroname-bo(11516)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739841223916&amp;w=2" source="BUGTRAQ" adv="1">20030310 QPopper 4.0.x buffer overflow vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html" source="SUSE">SuSE-SA:2003:018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792541215354&amp;w=2" source="GENTOO">GLSA-200303-12</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104768137314397&amp;w=2" source="BUGTRAQ">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104748775900481&amp;w=2" source="BUGTRAQ">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0144" published="2003-03-31" name="CVE-2003-0144" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7025" source="BID" patch="1" adv="1">7025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11473" source="XF" adv="1">lprm-bo(11473)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_014_lprold.html" source="SUSE">SuSE-SA:2003:0014</ref>
      <ref url="http://www.debian.org/security/2003/dsa-275" source="DEBIAN">DSA-275</ref>
      <ref url="http://www.debian.org/security/2003/dsa-267" source="DEBIAN">DSA-267</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P" source="SGI">20030406-02-P</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch" source="CONFIRM">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059" source="MANDRAKE">MDKSA-2003:059</ref>
      <ref url="http://secunia.com/advisories/8293" source="SECUNIA">8293</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104714441925019&amp;w=2" source="BUGTRAQ">20030308 OpenBSD lprm(1) exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104690434504429&amp;w=2" source="BUGTRAQ">20030305 potential buffer overflow in lprm (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lprold" name="lprold">
        <vers num="3.0.48" />
      </prod>
      <prod vendor="bsd" name="lpr">
        <vers num="0.48" />
        <vers num="2000-05-07" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0145" published="2003-03-31" name="CVE-2003-0145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tcpdump.org/tcpdump-changes.txt" source="CONFIRM" adv="1">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11857" source="XF">tcpdump-radius-attribute-dos(11857)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-214.html" source="REDHAT">RHSA-2003:214</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-151.html" source="REDHAT">RHSA-2003:151</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-032.html" source="REDHAT">RHSA-2003:032</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" source="MANDRAKE">MDKSA-2003:027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-261" source="DEBIAN">DSA-261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.5.2" />
        <vers num="3.6.2" />
        <vers num="3.7" />
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0146" published="2003-03-31" name="CVE-2003-0146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/630433" source="CERT-VN">VU#630433</ref>
      <ref url="http://www.debian.org/security/2003/dsa-263" source="DEBIAN" patch="1" adv="1">DSA-263</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11463" source="XF">netpbm-multiple-bo(11463)</ref>
      <ref url="http://www.securityfocus.com/bid/6979" source="BID">6979</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-060.html" source="REDHAT">RHSA-2003:060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104644687816522&amp;w=2" source="BUGTRAQ" adv="1">20030228 NetPBM, multiple vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656" source="CONECTIVA">CLSA-2003:656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netpbm" name="netpbm">
        <vers prev="1" num="9.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0147" published="2003-03-31" name="CVE-2003-0147" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/997481" source="CERT-VN" adv="1">VU#997481</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="BUGTRAQ">20030327 Immunix Secured OS 7+ openssl update</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-102.html" source="REDHAT">RHSA-2003:102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-101.html" source="REDHAT">RHSA-2003:101</ref>
      <ref url="http://www.openssl.org/news/secadv_20030317.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20030317.txt</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035" source="MANDRAKE">MDKSA-2003:035</ref>
      <ref url="http://www.debian.org/security/2003/dsa-288" source="DEBIAN">DSA-288</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792570615648&amp;w=2" source="BUGTRAQ" adv="1">20030317 [ADVISORY] Timing Attack on OpenSSL</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766550528628&amp;w=2" source="BUGTRAQ" adv="1">20030313 Vulnerability in OpenSSL</ref>
      <ref url="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf" source="MISC">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html" source="VULNWATCH" adv="1">20030313 OpenSSL Private Key Disclosure</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" source="SGI">20030501-01-I</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="IMMUNIX">IMNX-2003-7+-001-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html" source="OPENPKG">OpenPKG-SA-2003.019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml" source="GENTOO">GLSA-200303-23</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861762028637&amp;w=2" source="GENTOO">GLSA-200303-24</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104829040921835&amp;w=2" source="GENTOO">GLSA-200303-15</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104819602408063&amp;w=2" source="BUGTRAQ">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" source="CONECTIVA">CLA-2003:625</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" source="CALDERA">CSSA-2003-014.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:466" source="OVAL" sig="1">oval:org.mitre.oval:def:466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.7" />
        <vers num="0.9.7a" />
      </prod>
      <prod vendor="stunnel" name="stunnel">
        <vers num="3.10" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="3.14" />
        <vers num="3.15" />
        <vers num="3.16" />
        <vers num="3.17" />
        <vers num="3.18" />
        <vers num="3.19" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.9" />
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="4.02" />
        <vers num="4.03" />
        <vers num="4.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0148" published="2003-08-27" name="CVE-2003-0148" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" source="CONFIRM" patch="1" adv="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" source="ATSTAKE" patch="1" adv="1">A073103-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0" />
        <vers num="2.5" edition="sp1" />
        <vers num="2.5.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0149" published="2003-08-27" name="CVE-2003-0149" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" source="CONFIRM" patch="1" adv="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" source="ATSTAKE" patch="1" adv="1">A073103-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0" />
        <vers num="2.5" edition="sp1" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0150" published="2003-03-24" name="CVE-2003-0150" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/203897" source="CERT-VN">VU#203897</ref>
      <ref url="http://www.securityfocus.com/bid/7052" source="BID" patch="1" adv="1">7052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11510" source="XF">mysql-datadir-root-privileges(11510)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-093.html" source="REDHAT">RHSA-2003:093</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html" source="ENGARDE">ESA-20030324-012</ref>
      <ref url="http://www.debian.org/security/2003/dsa-303" source="DEBIAN">DSA-303</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-094.html" source="REDHAT">RHSA-2003:094</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285012750&amp;w=2" source="BUGTRAQ">20030318 GLSA:  mysql (200303-14)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739810523433&amp;w=2" source="BUGTRAQ">20030310 Re: MySQL user can be changed to root</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2" source="BUGTRAQ">20030308 MySQL_user_can_be_changed_to_root?</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" source="CONECTIVA">CLA-2003:743</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057" source="MANDRAKE">MDKSA-2003:057</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:442" source="OVAL" sig="1">oval:org.mitre.oval:def:442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.53a" />
        <vers num="3.23.54" />
        <vers num="3.23.54a" />
        <vers num="3.23.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0151" published="2003-03-24" name="CVE-2003-0151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792544515384&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792477914620&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express</ref>
      <ref url="http://www.s21sec.com/en/avisos/s21sec-011-en.txt" source="MISC">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</ref>
      <ref url="http://www.securityfocus.com/bid/7124" source="BID">7124</ref>
      <ref url="http://www.securityfocus.com/bid/7122" source="BID">7122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":express" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0152" published="2003-04-02" name="CVE-2003-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7162" source="BID" patch="1" adv="1">7162</ref>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0153" published="2003-04-02" name="CVE-2003-0153" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/9921" source="XF">bonsai-path-disclosure(9921)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" source="BUGTRAQ" adv="1">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=187230" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</ref>
      <ref url="http://www.securityfocus.com/bid/5517" source="BID">5517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0154" published="2003-04-02" name="CVE-2003-0154" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/5516" source="BID" patch="1" adv="1">5516</ref>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
      <ref url="http://www.iss.net/security_center/static/9920.php" source="XF">bonsai-error-message-xss(9920)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" source="BUGTRAQ" adv="1">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=163573" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=146244" source="MISC">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</ref>
      <ref url="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view" source="CONFIRM">http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view</ref>
      <ref url="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view" source="CONFIRM">http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0155" published="2003-04-02" name="CVE-2003-0155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7163" source="BID" patch="1" adv="1">7163</ref>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0156" published="2003-03-24" name="CVE-2003-0156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7062" source="BID" patch="1" adv="1">7062</ref>
      <ref url="http://www.debian.org/security/2003/dsa-264" source="DEBIAN" patch="1" adv="1">DSA-264</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739747222492&amp;w=2" source="BUGTRAQ" adv="1">20030311 Cross-Referencing Linux vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cross_referencer" name="lxr">
        <vers num="0.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0157" reject="1" published="2003-03-24" name="CVE-2003-0157" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2003-0158" reject="1" published="2003-03-24" name="CVE-2003-0158" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0159" published="2003-04-02" name="CVE-2003-0159" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7050" source="BID" patch="1" adv="1">7050</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" source="SUSE">SuSE-SA:2003:019</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051" source="MANDRAKE">MDKSA-2003:051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104741640924709&amp;w=2" source="BUGTRAQ">20030309 GLSA:  ethereal (200303-10)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:55" source="OVAL" sig="1">oval:org.mitre.oval:def:55</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.8.18" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0160" published="2003-04-02" name="CVE-2003-0160" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988" source="CONFIRM" patch="1">http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-112.html" source="REDHAT">RHSA-2003:112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:614" source="OVAL" sig="1">oval:org.mitre.oval:def:614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers prev="1" num="1.2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0161" published="2003-04-02" name="CVE-2003-0161" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-12.html" source="CERT" patch="1" adv="1">CA-2003-12</ref>
      <ref url="http://www.kb.cert.org/vuls/id/897604" source="CERT-VN">VU#897604</ref>
      <ref url="http://www.securityfocus.com/bid/7230" source="BID" patch="1" adv="1">7230</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-120.html" source="REDHAT" patch="1" adv="1">RHSA-2003:120</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-002-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-121.html" source="REDHAT">RHSA-2003:121</ref>
      <ref url="http://www.debian.org/security/2003/dsa-290" source="DEBIAN">DSA-290</ref>
      <ref url="http://www.debian.org/security/2003/dsa-278" source="DEBIAN">DSA-278</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001088.1-1" source="SUNALERT">1001088</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104897487512238&amp;w=2" source="BUGTRAQ" adv="1">20030329 Sendmail: -1 gone wild</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html" source="FULLDISC">20030329 Sendmail: -1 gone wild</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P" source="SGI">20030401-01-P</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt" source="SCO">SCOSA-2004.11</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc" source="FREEBSD">FreeBSD-SA-03:07</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt" source="CALDERA">CSSA-2003-016.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-002-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316961/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: sendmail (200303-27)</ref>
      <ref url="http://www.securityfocus.com/archive/1/321997" source="BUGTRAQ">20030520 [Fwd: 127 Research and Development: 127 Day!]</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml" source="GENTOO">GLSA-200303-27</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1" source="SUNALERT">52700</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1" source="SUNALERT">52620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914999806315&amp;w=2" source="BUGTRAQ">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104896621106790&amp;w=2" source="BUGTRAQ">20030329 sendmail 8.12.9 available</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614" source="CONECTIVA">CLA-2003:614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="8.10" />
        <vers num="8.10.1" />
        <vers num="8.10.2" />
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.11.6" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
        <vers num="8.12.0" />
        <vers num="8.12.1" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
        <vers num="8.9.0" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail_switch">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0b" />
        <vers num="4.0d" />
        <vers num="4.0d_pk9_bl17" />
        <vers num="4.0f" />
        <vers num="4.0f_pk6_bl17" />
        <vers num="4.0f_pk7_bl18" />
        <vers num="4.0g" />
        <vers num="4.0g_pk3_bl17" />
        <vers num="5.0" />
        <vers num="5.0_pk4_bl17" />
        <vers num="5.0_pk4_bl18" />
        <vers num="5.0a" />
        <vers num="5.0a_pk3_bl17" />
        <vers num="5.0f" />
        <vers num="5.1" />
        <vers num="5.1_pk3_bl17" />
        <vers num="5.1_pk4_bl18" />
        <vers num="5.1_pk5_bl19" />
        <vers num="5.1_pk6_bl20" />
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1b" />
        <vers num="5.1b_pk1_bl1" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.26" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="11.0.4" />
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
      <prod vendor="hp" name="hp-ux_series_700">
        <vers num="10.20" />
      </prod>
      <prod vendor="hp" name="hp-ux_series_800">
        <vers num="10.20" />
      </prod>
      <prod vendor="hp" name="sis">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0162" published="2003-04-02" name="CVE-2003-0162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6971" source="BID" patch="1" adv="1">6971</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11431" source="XF" adv="1">ecartis-password-reset(11431)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-271" source="DEBIAN">DSA-271</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673407728323&amp;w=2" source="BUGTRAQ" adv="1">20030303 Re: Ecardis Password Reseting Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636153214262&amp;w=2" source="BUGTRAQ">20030227 Ecardis Password Reseting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="1.0.0_snapshot_2002-10-13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0163" published="2003-05-05" name="CVE-2003-0163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7182" source="BID" patch="1" adv="1">7182</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0013.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0013.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013281120352&amp;w=2" source="BUGTRAQ">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gaim-encryption" name="gaim-encryption">
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0165" published="2003-04-02" name="CVE-2003-0165" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/363001" source="CERT-VN">VU#363001</ref>
      <ref url="http://www.securityfocus.com/bid/7121" source="BID" patch="1" adv="1">7121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-128.html" source="REDHAT" patch="1" adv="1">RHSA-2003:128</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887189724146&amp;w=2" source="BUGTRAQ">20030328 CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html" source="VULNWATCH">20030328 Vulnerability in GNOME's Eye of Gnome</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048" source="MANDRAKE">MDKSA-2003:048</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:52" source="OVAL" sig="1">oval:org.mitre.oval:def:52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="eog">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0166" published="2003-04-02" name="CVE-2003-0166" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7198" source="BID" adv="1">7198</ref>
      <ref url="http://www.securityfocus.com/bid/7197" source="BID" adv="1">7197</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869828526885&amp;w=2" source="BUGTRAQ" adv="1">20030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2" source="BUGTRAQ">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878100719467&amp;w=2" source="BUGTRAQ">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" source="CONECTIVA">CLSA-2003:691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0167" published="2003-04-02" name="CVE-2003-0167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7229" source="BID" patch="1" adv="1">7229</ref>
      <ref url="http://www.debian.org/security/2003/dsa-274" source="DEBIAN" patch="1" adv="1">DSA-274</ref>
      <ref url="http://www.debian.org/security/2003/dsa-300" source="DEBIAN">DSA-300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.3.12" />
        <vers num="1.3.12.1" />
        <vers num="1.3.16" />
        <vers num="1.3.17" />
        <vers num="1.3.22" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0168" published="2003-04-02" name="CVE-2003-0168" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/112553" source="CERT-VN">VU#112553</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded" source="BUGTRAQ">20030401 Fwd: QuickTime 6.1 for Windows is available</ref>
      <ref url="http://www.idefense.com/advisory/03.31.03.txt" source="MISC">http://www.idefense.com/advisory/03.31.03.txt</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00027.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00027.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html" source="VULNWATCH" adv="1">20030331 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11671" source="XF">quicktime-url-bo(11671)</ref>
      <ref url="http://www.securityfocus.com/bid/7247" source="BID">7247</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317148/30/25220/threaded" source="BUGTRAQ">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded" source="BUGTRAQ">20030401 Fwd: QuickTime 6.1 for Windows is available</ref>
      <ref url="http://www.osvdb.org/10561" source="OSVDB">10561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0169" published="2003-04-11" name="CVE-2003-0169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7246" source="BID" patch="1" adv="1">7246</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html" source="VULNWATCH" patch="1" adv="1">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914959705949&amp;w=2" source="BUGTRAQ">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="instant_toptools">
        <vers num="5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0170" published="2004-03-29" name="CVE-2003-0170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11823" source="XF" patch="1" adv="1">aix-ftpd-gain-access(11823)</ref>
      <ref url="http://www.securityfocus.com/bid/7346" source="BID" patch="1" adv="1">7346</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY42424" source="AIXAPAR" patch="1" adv="1">IY42424</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0469.1" source="IBM">MSS-OAR-E01-2003.0469.1</ref>
      <ref url="http://www.osvdb.org/4878" source="OSVDB">4878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0171" published="2003-05-05" name="CVE-2003-0171" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a041003-1.txt" source="ATSTAKE" adv="1">A041003-1</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0172" published="2003-04-02" name="CVE-2003-0172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7210" source="BID" patch="1" adv="1">7210</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878149020152&amp;w=2" source="BUGTRAQ" adv="1">20030327 @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11637" source="XF">php-openlog-stack-bo(11637)</ref>
      <ref url="http://www.securityfocus.com/archive/1/385238" source="BUGTRAQ">20041222 PHP v4.3.x exploit for Windows.</ref>
      <ref url="http://www.securityfocus.com/archive/1/316583" source="BUGTRAQ">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
      <ref url="http://www.osvdb.org/2113" source="OSVDB">2113</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2" source="BUGTRAQ">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0173" published="2003-05-05" name="CVE-2003-0173" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/111673" source="CERT-VN">VU#111673</ref>
      <ref url="http://www.debian.org/security/2003/dsa-283" source="DEBIAN" patch="1" adv="1">DSA-283</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P" source="SGI" patch="1" adv="1">20030404-01-P</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047" source="MANDRAKE">MDKSA-2003:047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfsdump" name="xfsdump">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0174" published="2003-05-12" name="CVE-2003-0174" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7442" source="BID" patch="1" adv="1">7442</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P" source="SGI" patch="1" adv="1">20030407-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11860" source="XF">irix-ldap-authentication-bypass(11860)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-084.shtml" source="CIAC">N-084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0175" published="2004-02-03" name="CVE-2003-0175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/142228" source="CERT-VN" patch="1" adv="1">VU#142228</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12241" source="XF" patch="1" adv="1">irix-piocswatch-ioctl-dos(12241)</ref>
      <ref url="http://www.securityfocus.com/bid/7868" source="BID" patch="1" adv="1">7868</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P" source="SGI" patch="1" adv="1">20030603-01-P</ref>
      <ref url="http://www.securitytracker.com/id?1008770" source="SECTRACK">1008770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0176" published="2003-08-18" name="CVE-2003-0176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0177" published="2003-08-18" name="CVE-2003-0177" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0178" published="2003-04-02" name="CVE-2003-0178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/772817" source="CERT-VN" patch="1" adv="1">VU#772817</ref>
      <ref url="http://www.kb.cert.org/vuls/id/542873" source="CERT-VN">VU#542873</ref>
      <ref url="http://www.kb.cert.org/vuls/id/206361" source="CERT-VN">VU#206361</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/6871" source="BID" patch="1" adv="1">6871</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431461&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11337" source="XF" adv="1">lotus-domino-hostname-bo(11337)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11336" source="XF">lotus-domino-inotes-bo(11336)</ref>
      <ref url="http://www.securityfocus.com/bid/6870" source="BID">6870</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt" source="MISC">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt" source="MISC">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" source="NTBUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777531350&amp;w=2" source="NTBUGTRAQ">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777331345&amp;w=2" source="NTBUGTRAQ">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2" source="BUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431463&amp;w=2" source="BUGTRAQ">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" source="VULNWATCH">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html" source="VULNWATCH">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html" source="VULNWATCH">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0179" published="2003-04-02" name="CVE-2003-0179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/571297" source="CERT-VN" patch="1" adv="1">VU#571297</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/6872" source="BID" patch="1" adv="1">6872</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550124032513&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11339" source="XF">lotus-notes-activex-bo(11339)</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt" source="MISC">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21104543" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" source="NTBUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778131373&amp;w=2" source="NTBUGTRAQ">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2" source="BUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" source="VULNWATCH">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0" />
      </prod>
      <prod vendor="ibm" name="lotus_notes_client">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0180" published="2003-04-02" name="CVE-2003-0180" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/355169" source="CERT-VN" patch="1" adv="1">VU#355169</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT" patch="1" adv="1">CA-2003-11</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-60dos.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11360" source="XF">lotus-incomplete-post-dos(11360)</ref>
      <ref url="http://www.securityfocus.com/bid/6951" source="BID">6951</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" source="VULNWATCH">20030218 More Lotus Domino Advisories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0181" published="2003-04-02" name="CVE-2003-0181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT" patch="1" adv="1">CA-2003-11</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-60dos.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11361" source="XF">lotus-invalid-field-dos(11361)</ref>
      <ref url="http://www.securityfocus.com/bid/6951" source="BID">6951</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" source="VULNWATCH">20030218 More Lotus Domino Advisories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0187" published="2003-08-27" name="CVE-2003-0187" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105986028426824&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030802 [SECURITY] Netfilter Security Advisory: Conntrack list_del() DoS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:260" source="OVAL" sig="1">oval:org.mitre.oval:def:260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0188" published="2003-06-09" name="CVE-2003-0188" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-169.html" source="REDHAT" patch="1" adv="1">RHSA-2003:169</ref>
      <ref url="http://www.debian.org/security/2003/dsa-304" source="DEBIAN" patch="1" adv="1">DSA-304</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-35.txt" source="TURBO">TLSA-2003-35</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-167.html" source="REDHAT">RHSA-2003:167</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:430" source="OVAL" sig="1">oval:org.mitre.oval:def:430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lv" name="lv">
        <vers num="4.49.1" />
        <vers num="4.49.2" />
        <vers num="4.49.3" />
        <vers num="4.49.4" />
      </prod>
      <prod vendor="redhat" name="lv">
        <vers num="4.49.4-1" edition="" />
        <vers num="4.49.4-1" edition=":i386" />
        <vers num="4.49.4-3" edition="" />
        <vers num="4.49.4-3" edition=":i386" />
        <vers num="4.49.4-7" edition="" />
        <vers num="4.49.4-7" edition=":i386" />
        <vers num="4.49.4-9" edition="" />
        <vers num="4.49.4-9" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0189" published="2003-06-09" name="CVE-2003-0189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/479268" source="CERT-VN">VU#479268</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-186.html" source="REDHAT" patch="1" adv="1">RHSA-2003:186</ref>
      <ref url="http://www.apache.org/dist/httpd/Announcement2.html" source="CONFIRM" patch="1" adv="1">http://www.apache.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12091" source="XF">apache-aprpasswordvalidate-dos(12091)</ref>
      <ref url="http://www.securityfocus.com/bid/7725" source="BID">7725</ref>
      <ref url="http://secunia.com/advisories/8881" source="SECUNIA">8881</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" source="CONECTIVA">CLA-2003:661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0190" published="2003-05-12" name="CVE-2003-0190" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7467" source="BID" patch="1" adv="1">7467</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-31.txt" source="TURBO">TLSA-2003-31</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-224.html" source="REDHAT">RHSA-2003:224</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-222.html" source="REDHAT">RHSA-2003:222</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018677302607&amp;w=2" source="BUGTRAQ">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html" source="FULLDISC">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://lab.mediaservice.net/advisory/2003-01-openssh.txt" source="MISC">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:445" source="OVAL" sig="1">oval:org.mitre.oval:def:445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.4p1" />
        <vers num="3.6.1p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0192" published="2003-08-18" name="CVE-2003-0192" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-240.html" source="REDHAT" patch="1" adv="1">RHSA-2003:240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-243.html" source="REDHAT">RHSA-2003:243</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" source="SCO">SCOSA-2004.6</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-244.html" source="REDHAT">RHSA-2003:244</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" source="MANDRAKE">MDKSA-2003:075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:169" source="OVAL" sig="1">oval:org.mitre.oval:def:169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0193" published="2004-08-18" name="CVE-2003-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-575" source="DEBIAN">DSA-575</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16335" source="XF">catdoc-xlsview-symlink(16335)</ref>
      <ref url="http://www.securityfocus.com/bid/11560" source="BID">11560</ref>
      <ref url="http://www.osvdb.org/11193" source="OSVDB">11193</ref>
      <ref url="http://secunia.com/advisories/13022/" source="SECUNIA">13022</ref>
      <ref url="http://secunia.com/advisories/13021/" source="SECUNIA">13021</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="catdoc" name="catdoc">
        <vers prev="1" num="0.91" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0194" published="2003-06-09" name="CVE-2003-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">tcpdump does not properly drop privileges to the pcap user when starting up.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-174.html" source="REDHAT" patch="1" adv="1">RHSA-2003:174</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-151.html" source="REDHAT">RHSA-2003:151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="tcpdump">
        <vers num="3.4-39" edition="" />
        <vers num="3.4-39" edition=":i386" />
        <vers num="3.6.2-12" edition="" />
        <vers num="3.6.2-12" edition=":i386" />
        <vers num="3.6.2-9" edition="" />
        <vers num="3.6.2-9" edition=":i386" />
        <vers num="3.6.2-9" edition=":ia64" />
        <vers num="3.6.3-3" edition="" />
        <vers num="3.6.3-3" edition=":i386" />
        <vers num="3.7.2-1" edition="" />
        <vers num="3.7.2-1" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0195" published="2003-06-16" name="CVE-2003-0195" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-171.html" source="REDHAT" patch="1" adv="1">RHSA-2003:171</ref>
      <ref url="http://www.debian.org/security/2003/dsa-317" source="DEBIAN" patch="1" adv="1">DSA-317</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-33.txt" source="TURBO">TLSA-2003-33</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_028.html" source="SUSE">SuSE-SA:2003:028</ref>
      <ref url="http://www.securityfocus.com/bid/7637" source="BID">7637</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:062" source="MANDRAKE">MDKSA-2003:062</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427288724449&amp;w=2" source="BUGTRAQ">20030529 [slackware-security]  CUPS DoS vulnerability fixed (SSA:2003-149-01)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000678" source="CONECTIVA">CLSA-2003:678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6" source="OVAL" sig="1">oval:org.mitre.oval:def:6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="8.1" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0196" published="2003-05-05" name="CVE-2003-0196" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-137.html" source="REDHAT" patch="1" adv="1">RHSA-2003:137</ref>
      <ref url="http://www.debian.org/security/2003/dsa-280" source="DEBIAN" patch="1" adv="1">DSA-280</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104973186901597&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030407 [OpenPKG-SA-2003.028] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" source="MANDRAKE">MDKSA-2003:044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2" source="BUGTRAQ">20030407 Immunix Secured OS 7+ samba update</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:564" source="OVAL" sig="1">oval:org.mitre.oval:def:564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="cifs-9000_server">
        <vers num="a.01.05" />
        <vers num="a.01.06" />
        <vers num="a.01.07" />
        <vers num="a.01.08" />
        <vers num="a.01.08.01" />
        <vers num="a.01.09" />
        <vers num="a.01.09.01" />
        <vers num="a.01.09.02" />
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.1a" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
        <vers num="2.2.8" />
      </prod>
      <prod vendor="samba-tng" name="samba-tng">
        <vers num="0.3" />
        <vers num="0.3.1" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0b" />
        <vers num="4.0d" />
        <vers num="4.0d_pk9_bl17" />
        <vers num="4.0f" />
        <vers num="4.0f_pk6_bl17" />
        <vers num="4.0f_pk7_bl18" />
        <vers num="4.0g" />
        <vers num="4.0g_pk3_bl17" />
        <vers num="5.0" />
        <vers num="5.0_pk4_bl17" />
        <vers num="5.0_pk4_bl18" />
        <vers num="5.0a" />
        <vers num="5.0a_pk3_bl17" />
        <vers num="5.0f" />
        <vers num="5.1" />
        <vers num="5.1_pk3_bl17" />
        <vers num="5.1_pk4_bl18" />
        <vers num="5.1_pk5_bl19" />
        <vers num="5.1_pk6_bl20" />
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1b" />
        <vers num="5.1b_pk1_bl1" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0197" published="2003-04-11" name="CVE-2003-0197" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt" source="MISC" patch="1" adv="1">http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104940730819887&amp;w=2" source="BUGTRAQ">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html" source="VULNWATCH">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="interbase">
        <vers num="6.0" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0198" published="2003-05-05" name="CVE-2003-0198" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0201" published="2003-05-05" name="CVE-2003-0201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/267873" source="CERT-VN">VU#267873</ref>
      <ref url="http://www.securityfocus.com/bid/7294" source="BID" patch="1" adv="1">7294</ref>
      <ref url="http://www.debian.org/security/2003/dsa-280" source="DEBIAN" patch="1" adv="1">DSA-280</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104972664226781&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030407 [DDI-1013] Buffer Overflow in Samba allows remote root compromise</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-137.html" source="REDHAT">RHSA-2003:137</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_025_samba.html" source="SUSE">SuSE-SA:2003:025</ref>
      <ref url="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt" source="MISC">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P" source="SGI">20030403-01-P</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" source="MANDRAKE">MDKSA-2003:044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994564212488&amp;w=2" source="BUGTRAQ">20030409 GLSA:  samba (200304-02)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104981682014565&amp;w=2" source="BUGTRAQ">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2" source="BUGTRAQ">20030407 Immunix Secured OS 7+ samba update</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624" source="CONECTIVA">CLA-2003:624</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:567" source="OVAL" sig="1">oval:org.mitre.oval:def:567</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2163" source="OVAL" sig="1">oval:org.mitre.oval:def:2163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="cifs-9000_server">
        <vers num="a.01.05" />
        <vers num="a.01.06" />
        <vers num="a.01.07" />
        <vers num="a.01.08" />
        <vers num="a.01.08.01" />
        <vers num="a.01.09" />
        <vers num="a.01.09.01" />
        <vers num="a.01.09.02" />
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.1a" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
        <vers num="2.2.8" />
      </prod>
      <prod vendor="samba-tng" name="samba-tng">
        <vers num="0.3" />
        <vers num="0.3.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0b" />
        <vers num="4.0d" />
        <vers num="4.0d_pk9_bl17" />
        <vers num="4.0f" />
        <vers num="4.0f_pk6_bl17" />
        <vers num="4.0f_pk7_bl18" />
        <vers num="4.0g" />
        <vers num="4.0g_pk3_bl17" />
        <vers num="5.0" />
        <vers num="5.0_pk4_bl17" />
        <vers num="5.0_pk4_bl18" />
        <vers num="5.0a" />
        <vers num="5.0a_pk3_bl17" />
        <vers num="5.0f" />
        <vers num="5.1" />
        <vers num="5.1_pk3_bl17" />
        <vers num="5.1_pk4_bl18" />
        <vers num="5.1_pk5_bl19" />
        <vers num="5.1_pk6_bl20" />
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1b" />
        <vers num="5.1b_pk1_bl1" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0202" published="2004-04-15" name="CVE-2003-0202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-279" source="DEBIAN" patch="1" adv="1">DSA-279</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11734" source="XF" adv="1">metrics-tmpfile-symlink(11734)</ref>
      <ref url="http://www.securityfocus.com/bid/7293" source="BID" adv="1">7293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brian_renaud" name="metrics">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0203" published="2003-04-11" name="CVE-2003-0203" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6921" source="BID" patch="1" adv="1">6921</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11399" source="XF" adv="1">moxftp-welcome-banner-bo(11399)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-281" source="DEBIAN">DSA-281</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2" source="BUGTRAQ" adv="1">20030223 moxftp arbitrary code execution poc/advisory</ref>
      <ref url="http://www.securitytracker.com/id?1006156" source="SECTRACK">1006156</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html" source="FULLDISC">20030223 moxftp arbitrary code execution poc/advisory</ref>
      <ref url="http://secunia.com/advisories/8136" source="SECUNIA">8136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moxftp" name="moxftp">
        <vers num="2.2" />
      </prod>
      <prod vendor="xftp" name="xftp">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0204" published="2003-05-05" name="CVE-2003-0204" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20030409-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20030409-1.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-284" source="DEBIAN" patch="1" adv="1">DSA-284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-002.html" source="REDHAT">RHSA-2003:002</ref>
      <ref url="http://www.debian.org/security/2003/dsa-296" source="DEBIAN">DSA-296</ref>
      <ref url="http://www.debian.org/security/2003/dsa-293" source="DEBIAN">DSA-293</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=56808" source="CONFIRM">http://bugs.kde.org/show_bug.cgi?id=56808</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=53343" source="CONFIRM">http://bugs.kde.org/show_bug.cgi?id=53343</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049" source="MANDRAKE">MDKSA-2003:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105034222521369&amp;w=2" source="BUGTRAQ">20030414 GLSA:  kde-2.x (200304-05.1)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105017403010459&amp;w=2" source="BUGTRAQ">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105012994719099&amp;w=2" source="BUGTRAQ">20030411 GLSA:  kde-2.x (200304-05)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001557020141&amp;w=2" source="BUGTRAQ">20030410 GLSA:  kde-3.x (200304-04)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" source="CONECTIVA">CLA-2003:747</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668" source="CONECTIVA">CLA-2003:668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.3a" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.5a" />
        <vers num="3.1" />
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0205" published="2003-05-12" name="CVE-2003-0205" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-294" source="DEBIAN" patch="1" adv="1">DSA-294</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030423 Security problems in gkrellm-newsticker</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gkrellm_newsticker" name="gkrellm_newsticker">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0206" published="2003-05-12" name="CVE-2003-0206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-294" source="DEBIAN" patch="1" adv="1">DSA-294</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030423 Security problems in gkrellm-newsticker</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gkrellm_newsticker" name="gkrellm_newsticker">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0207" published="2003-05-05" name="CVE-2003-0207" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-286" source="DEBIAN" patch="1" adv="1">DSA-286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gs-common" name="gs-common">
        <vers num="0.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0208" published="2003-05-05" name="CVE-2003-0208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/securitynews/5XP0B0U9PE.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/securitynews/5XP0B0U9PE.html</ref>
      <ref url="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html" source="FULLDISC">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105033712615013&amp;w=2" source="BUGTRAQ">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="flash">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0209" published="2003-05-05" name="CVE-2003-0209" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/139129" source="CERT-VN" adv="1">VU#139129</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-13.html" source="CERT">CA-2003-13</ref>
      <ref url="http://www.securityfocus.com/bid/7178" source="BID" patch="1" adv="1">7178</ref>
      <ref url="http://www.debian.org/security/2003/dsa-297" source="DEBIAN">DSA-297</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172790914107&amp;w=2" source="ENGARDE">ESA-20030430-013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2" source="BUGTRAQ">20030428 GLSA:  snort (200304-06)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111217731583&amp;w=2" source="BUGTRAQ">20030423 Snort &lt;=1.9.1 exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105103586927007&amp;w=2" source="BUGTRAQ">20030422 GLSA:  snort (200304-05)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105043563016235&amp;w=2" source="BUGTRAQ">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052" source="MANDRAKE">MDKSA-2003:052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smoothwall" name="smoothwall">
        <vers num="2.0_beta_4" />
      </prod>
      <prod vendor="sourcefire" name="snort">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0210" published="2003-05-12" name="CVE-2003-0210" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/697049" source="CERT-VN">VU#697049</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml" source="CISCO" patch="1" adv="1">20030423 Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120066126196&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105118056332344&amp;w=2" source="NTBUGTRAQ">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.1" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.3" />
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0211" published="2003-05-05" name="CVE-2003-0211" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068673220605&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030418 Xinetd 2.3.10 Memory Leaks</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-160.html" source="REDHAT">RHSA-2003:160</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056" source="MANDRAKE">MDKSA-2003:056</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782" source="CONECTIVA">CLA-2003:782</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:657" source="OVAL" sig="1">oval:org.mitre.oval:def:657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xinetd" name="xinetd">
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0212" published="2003-05-12" name="CVE-2003-0212" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-289" source="DEBIAN" patch="1" adv="1">DSA-289</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105059298502830&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030417 Vulnerability in rinetd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rinetd" name="rinetd">
        <vers num="0.52" />
        <vers num="0.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0213" published="2003-05-12" name="CVE-2003-0213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/673993" source="CERT-VN">VU#673993</ref>
      <ref url="http://www.securityfocus.com/bid/7316" source="BID" patch="1" adv="1">7316</ref>
      <ref url="http://www.securityfocus.com/archive/1/317995" source="BUGTRAQ" patch="1" adv="1">20030409 PoPToP PPTP server remotely exploitable buffer overflow</ref>
      <ref url="http://www.debian.org/security/2003/dsa-295" source="DEBIAN" patch="1" adv="1">DSA-295</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_029.html" source="SUSE">SuSE-SA:2003:029</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068728421160&amp;w=2" source="BUGTRAQ" adv="1">20030418 Exploit for PoPToP PPTP server</ref>
      <ref url="http://www.securityfocus.com/archive/1/319428" source="BUGTRAQ">20030422 Re: Exploit for PoPToP PPTP server - Linux version</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=138437" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=138437</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154539727967&amp;w=2" source="BUGTRAQ">20030428 GLSA:  pptpd (200304-08)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poptop" name="pptp_server">
        <vers num="1.0.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.3_2002-10-09" />
        <vers num="1.1.4b1" />
        <vers num="1.1.4b2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0214" published="2003-05-12" name="CVE-2003-0214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-292" source="DEBIAN" patch="1" adv="1">DSA-292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="mime-support">
        <vers num="3.10" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="3.14" />
        <vers num="3.15" />
        <vers num="3.16" />
        <vers num="3.17" />
        <vers num="3.18" />
        <vers num="3.19" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0215" published="2003-05-12" name="CVE-2003-0215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812" source="CONFIRM" patch="1" adv="1">http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120052725940&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030424 SQL injection in BttlxeForum</ref>
      <ref url="http://securitytracker.com/id?1006632" source="SECTRACK">1006632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleaxe_software" name="bttlxeforum">
        <vers prev="1" num="2.0_beta_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0216" published="2003-05-12" name="CVE-2003-0216" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/443257" source="CERT-VN">VU#443257</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml." source="CISCO">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catos">
        <vers num="7.5(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0217" published="2003-06-16" name="CVE-2003-0217" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105283833617480&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 XSS In Neoteris IVE Allows Session Hijacking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0218" published="2003-05-12" name="CVE-2003-0218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7202" source="BID" patch="1" adv="1">7202</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154473526898&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030428 GLSA:  monkeyd (200304-07.1)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html" source="VULNWATCH" patch="1" adv="1">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
      <ref url="http://monkeyd.sourceforge.net/Changelog.txt" source="CONFIRM">http://monkeyd.sourceforge.net/Changelog.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105094204204166&amp;w=2" source="BUGTRAQ">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey" name="monkey_http_daemon">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0219" published="2003-05-12" name="CVE-2003-0219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/641012" source="CERT-VN">VU#641012</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
      <ref url="http://www.securityfocus.com/bid/7179" source="BID">7179</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2" source="BUGTRAQ">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall_2">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0220" published="2003-05-12" name="CVE-2003-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/454716" source="CERT-VN">VU#454716</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
      <ref url="http://www.securityfocus.com/bid/7180" source="BID">7180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2" source="BUGTRAQ">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall_2">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0221" published="2003-05-12" name="CVE-2003-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11892" source="XF">tru64-dupatch-setld-symlink(11892)</ref>
      <ref url="http://www.securityfocus.com/bid/7452" source="BID">7452</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-086.shtml" source="HP">SSRT3471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="tru64">
        <vers prev="1" num="5.1b" edition="pk1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0222" published="2003-05-12" name="CVE-2003-0222" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7453" source="BID" patch="1" adv="1">7453</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11885" source="XF">oracle-database-link-bo(11885)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-085.shtml" source="CIAC">N-085</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105163376015735&amp;w=2" source="NTBUGTRAQ">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105162831008176&amp;w=2" source="BUGTRAQ">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.5.1" />
        <vers num="8.0.6" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="9.2.1" />
        <vers num="9.2.2" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.0.6" />
        <vers num="8.0.6.3" />
        <vers num="8.0x" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.7.1" />
        <vers num="8.1.7.4" />
        <vers num="8.1x" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.1.2" />
        <vers num="9.0.1.3" />
        <vers num="9.0.1.4" />
        <vers num="9.0.2" />
        <vers num="9.2.0.1" />
        <vers num="9.2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0223" published="2003-06-09" name="CVE-2003-0223" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:66" source="OVAL" sig="1">oval:org.mitre.oval:def:66</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0224" published="2003-06-09" name="CVE-2003-0224" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105431767100944&amp;w=2" source="NTBUGTRAQ">20030530 NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:483" source="OVAL" sig="1">oval:org.mitre.oval:def:483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0225" published="2003-06-09" name="CVE-2003-0225" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://www.aqtronix.com/Advisories/AQ-2003-01.txt" source="MISC">http://www.aqtronix.com/Advisories/AQ-2003-01.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105110606122772&amp;w=2" source="NTBUGTRAQ">20030418 Microsoft Active Server Pages DoS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:373" source="OVAL" sig="1">oval:org.mitre.oval:def:373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0226" published="2003-06-09" name="CVE-2003-0226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.spidynamics.com/iis_alert.html" source="MISC" patch="1" adv="1">http://www.spidynamics.com/iis_alert.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0308.html" source="BUGTRAQ" patch="1" adv="1">20030528 Internet Information Services 5.0 Denial of service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421243732552&amp;w=2" source="NTBUGTRAQ">20030528 Internet Information Services 5.0 Denial of service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427362724860&amp;w=2" source="BUGTRAQ">20030529 IIS WEBDAV Denial of Service attacks</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:933" source="OVAL" sig="1">oval:org.mitre.oval:def:933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0227" published="2003-06-09" name="CVE-2003-0227" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-019.asp" source="MS" patch="1" adv="1">MS03-019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421176432011&amp;w=2" source="NTBUGTRAQ">20030528 MS03-019: DoS or Code of Choice</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421127531558&amp;w=2" source="NTBUGTRAQ">20030528 Re: Alert: MS03-019, Microsoft... wrong, again.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427615626177&amp;w=2" source="BUGTRAQ">20030528 RE: Alert: MS03-019, Microsoft... wrong, again.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:966" source="OVAL" sig="1">oval:org.mitre.oval:def:966</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:936" source="OVAL" sig="1">oval:org.mitre.oval:def:936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0228" published="2003-05-27" name="CVE-2003-0228" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/384932" source="CERT-VN">VU#384932</ref>
      <ref url="http://www.securityfocus.com/bid/7517" source="BID" patch="1" adv="1">7517</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-017.asp" source="MS" patch="1" adv="1">MS03-017</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232913516488&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030507 Windows Media Player directory traversal vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11953" source="XF">mediaplayer-skin-code-execution(11953)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233960728901&amp;w=2" source="NTBUGTRAQ">20030507 Windows Media Player directory traversal vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240528419389&amp;w=2" source="BUGTRAQ">20030508 why i love xs4all + mediaplayer thingie</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:321" source="OVAL" sig="1">oval:org.mitre.oval:def:321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="7.1" />
        <vers num="xp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0230" published="2003-08-27" name="CVE-2003-0230" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/556356" source="CERT-VN">VU#556356</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp" source="MS" patch="1">MS03-031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:235" source="OVAL" sig="1">oval:org.mitre.oval:def:235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":desktop_engine" />
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sp3a" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0231" published="2003-08-27" name="CVE-2003-0231" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/918652" source="CERT-VN">VU#918652</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp" source="MS">MS03-031</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a072303-2.txt" source="ATSTAKE">A072303-2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:299" source="OVAL" sig="1">oval:org.mitre.oval:def:299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":desktop_engine" />
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sp3a" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0232" published="2003-08-27" name="CVE-2003-0232" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/584868" source="CERT-VN">VU#584868</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp" source="MS" patch="1" adv="1">MS03-031</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a072303-3.txt" source="ATSTAKE" patch="1" adv="1">A072303-3</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:303" source="OVAL" sig="1">oval:org.mitre.oval:def:303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":desktop_engine" />
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sp3a" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0233" published="2003-05-12" name="CVE-2003-0233" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120164927952&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030424 Internet Explorer Plugin.ocx heap overflow (#NISR24042003)</ref>
      <ref url="http://www.iss.net/security_center/static/11854.php" source="XF" adv="1">ie-plugin-load-bo(11854)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1094" source="OVAL" sig="1">oval:org.mitre.oval:def:1094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0235" published="2003-05-27" name="CVE-2003-0235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7461" source="BID" adv="1">7461</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11938" source="XF">icq-pop3-format-string(11938)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a" />
        <vers num="2000.0b_build3278" />
        <vers num="2001a" />
        <vers num="2001b_build3636" />
        <vers num="2001b_build3638" />
        <vers num="2001b_build3659" />
        <vers num="2002a_build3722" />
        <vers num="2002a_build3727" />
        <vers num="2003a_build3777" />
        <vers num="2003a_build3799" />
        <vers num="2003a_build3800" />
        <vers num="99a_2.15build1701" />
        <vers num="99a_2.21build1800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0236" published="2003-05-27" name="CVE-2003-0236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7463" source="BID" adv="1">7463</ref>
      <ref url="http://www.securityfocus.com/bid/7462" source="BID" adv="1">7462</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11939" source="XF">icq-pop3-email-bo(11939)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a" />
        <vers num="2000.0b_build3278" />
        <vers num="2001a" />
        <vers num="2001b_build3636" />
        <vers num="2001b_build3638" />
        <vers num="2001b_build3659" />
        <vers num="2002a_build3722" />
        <vers num="2002a_build3727" />
        <vers num="2003a_build3777" />
        <vers num="2003a_build3799" />
        <vers num="2003a_build3800" />
        <vers num="99a_2.15build1701" />
        <vers num="99a_2.21build1800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0237" published="2003-05-27" name="CVE-2003-0237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7464" source="BID" patch="1" adv="1">7464</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11944" source="XF">icq-features-no-auth(11944)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a" />
        <vers num="2000.0b_build3278" />
        <vers num="2001a" />
        <vers num="2001b_build3636" />
        <vers num="2001b_build3638" />
        <vers num="2001b_build3659" />
        <vers num="2002a_build3722" />
        <vers num="2002a_build3727" />
        <vers num="2003a_build3777" />
        <vers num="2003a_build3799" />
        <vers num="2003a_build3800" />
        <vers num="99a_2.15build1701" />
        <vers num="99a_2.21build1800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0238" published="2003-05-27" name="CVE-2003-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7465" source="BID" adv="1">7465</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11947" source="XF">icq-table-tag-dos(11947)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a" />
        <vers num="2000.0b_build3278" />
        <vers num="2001a" />
        <vers num="2001b_build3636" />
        <vers num="2001b_build3638" />
        <vers num="2001b_build3659" />
        <vers num="2002a_build3722" />
        <vers num="2002a_build3727" />
        <vers num="2003a_build3777" />
        <vers num="2003a_build3799" />
        <vers num="2003a_build3800" />
        <vers num="99a_2.15build1701" />
        <vers num="99a_2.21build1800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0239" published="2003-05-27" name="CVE-2003-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7466" source="BID" adv="1">7466</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11948" source="XF">icq-gif89a-header-dos(11948)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a" />
        <vers num="2000.0b_build3278" />
        <vers num="2001a" />
        <vers num="2001b_build3636" />
        <vers num="2001b_build3638" />
        <vers num="2001b_build3659" />
        <vers num="2002a_build3722" />
        <vers num="2002a_build3727" />
        <vers num="2003a_build3777" />
        <vers num="2003a_build3799" />
        <vers num="2003a_build3800" />
        <vers num="99a_2.15build1701" />
        <vers num="99a_2.21build1800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0240" published="2003-06-09" name="CVE-2003-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/799060" source="CERT-VN">VU#799060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12104" source="XF">axis-admin-authentication-bypass(12104)</ref>
      <ref url="http://www.securityfocus.com/bid/7652" source="BID">7652</ref>
      <ref url="http://securitytracker.com/id?1006854" source="SECTRACK">1006854</ref>
      <ref url="http://secunia.com/advisories/8876" source="SECUNIA">8876</ref>
      <ref url="http://www.osvdb.org/4804" source="OSVDB">4804</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406374731579&amp;w=2" source="BUGTRAQ">20030527 CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axis" name="2100_network_camera">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2110_network_camera">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2120_network_camera">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2130_ptz_network_camera">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2400_video_server">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2401_video_server">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2420_network_camera">
        <vers prev="1" num="2.32" />
      </prod>
      <prod vendor="axis" name="2460_network_dvr">
        <vers prev="1" num="3.00" />
      </prod>
      <prod vendor="axis" name="250s_video_server">
        <vers prev="1" num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0241" published="2003-06-09" name="CVE-2003-0241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.secnap.net/security/gm001.html" source="MISC" patch="1" adv="1">http://www.secnap.net/security/gm001.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0091.html" source="VULNWATCH" patch="1" adv="1">20030528 SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frontrange" name="goldmine">
        <vers num="5.70" />
        <vers num="6.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0242" published="2003-06-09" name="CVE-2003-0242" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/869548" source="CERT-VN">VU#869548</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12027" source="XF">macos-ipsec-acl-bypass(12027)</ref>
      <ref url="http://www.securityfocus.com/bid/7628" source="BID">7628</ref>
      <ref url="http://securitytracker.com/id?1006796" source="SECTRACK">1006796</ref>
      <ref url="http://secunia.com/advisories/8798" source="SECUNIA">8798</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0243" published="2003-05-27" name="CVE-2003-0243" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1006707" source="SECTRACK">1006707</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0058.html" source="VULNWATCH">20030507 Happymall E-Commerce Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="happycgi" name="happymall">
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0244" published="2003-05-27" name="CVE-2003-0244" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-145.html" source="REDHAT" patch="1" adv="1">RHSA-2003:145</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-172.html" source="REDHAT">RHSA-2003:172</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-147.html" source="REDHAT">RHSA-2003:147</ref>
      <ref url="http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html" source="MISC">http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105595901923063&amp;w=2" source="BUGTRAQ">20030618 [slackware-security]  2.4.21 kernels available (SSA:2003-168-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" source="ENGARDE">ESA-20030515-017</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0073.html" source="VULNWATCH">20030517 Algorithmic Complexity Attacks and the Linux Networking Code</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15382" source="XF">data-algorithmic-complexity-dos(15382)</ref>
      <ref url="http://www.securityfocus.com/bid/7601" source="BID">7601</ref>
      <ref url="http://www.secunia.com/advisories/8786/" source="SECUNIA">8786</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=104956079213417" source="MISC">http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=104956079213417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:261" source="OVAL" sig="1">oval:org.mitre.oval:def:261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0245" published="2003-06-09" name="CVE-2003-0245" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757612" source="CERT-VN" adv="1">VU#757612</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-186.html" source="REDHAT" patch="1" adv="1">RHSA-2003:186</ref>
      <ref url="http://www.apache.org/dist/httpd/Announcement2.html" source="CONFIRM" patch="1" adv="1">http://www.apache.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12090" source="XF">apache-aprpsprintf-code-execution(12090)</ref>
      <ref url="http://www.securityfocus.com/bid/7723" source="BID">7723</ref>
      <ref url="http://www.idefense.com/advisory/05.30.03.txt" source="MISC">http://www.idefense.com/advisory/05.30.03.txt </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html" source="VULNWATCH">20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:063" source="MANDRAKE">MDKSA-2003:063</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" source="CONECTIVA">CLA-2003:661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0246" published="2003-06-16" name="CVE-2003-0246" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-172.html" source="REDHAT" patch="1" adv="1">RHSA-2003:172</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" source="ENGARDE" patch="1" adv="1">ESA-20030515-017</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-147.html" source="REDHAT">RHSA-2003:147</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html" source="VULNWATCH">20030520 Linux 2.4 kernel ioperm vuln</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:278" source="OVAL" sig="1">oval:org.mitre.oval:def:278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0247" published="2003-06-16" name="CVE-2003-0247" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-187.html" source="REDHAT" patch="1" adv="1">RHSA-2003:187</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-195.html" source="REDHAT">RHSA-2003:195</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:284" source="OVAL" sig="1">oval:org.mitre.oval:def:284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0248" published="2003-06-16" name="CVE-2003-0248" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-187.html" source="REDHAT" patch="1" adv="1">RHSA-2003:187</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-195.html" source="REDHAT">RHSA-2003:195</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:292" source="OVAL" sig="1">oval:org.mitre.oval:def:292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0249" published="2003-12-31" name="CVE-2003-0249" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive.  NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method.  A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods.  It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=97" source="IDEFENSE" adv="1">20030625 PHP/Apache .htaccess Authentication Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0251" published="2003-07-24" name="CVE-2003-0251" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-173.html" source="REDHAT" patch="1" adv="1">RHSA-2003:173</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2873" source="VUPEN">ADV-2006-2873</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-43.txt" source="TURBO">TLSA-2003-43</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440454/100/0/threaded" source="HP">SSRT061154</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55600&amp;zone_32=category%3Asecurity" source="SUNALERT">55600</ref>
      <ref url="http://www.securityfocus.com/bid/8031" source="BID">8031</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440454/100/0/threaded" source="HP">HPSBTU02132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-201.html" source="REDHAT">RHSA-2003:201</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:072" source="MANDRAKE">MDKSA-2003:072</ref>
      <ref url="http://securitytracker.com/id?1016517" source="SECTRACK">1016517</ref>
      <ref url="http://secunia.com/advisories/21112" source="SECUNIA">21112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:667" source="OVAL" sig="1">oval:org.mitre.oval:def:667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nis" name="ypserv_nis_server">
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0252" published="2003-08-18" name="CVE-2003-0252" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/258564" source="CERT-VN">VU#258564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830921519513&amp;w=2" source="BUGTRAQ" patch="1">20030715 [slackware-security]  nfs-utils packages replaced (SSA:2003-195-01b)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12600" source="XF">nfs-utils-offbyone-bo(12600)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-44.txt" source="TURBO">TLSA-2003-44</ref>
      <ref url="http://www.securityfocus.com/bid/8179" source="BID">8179</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-207.html" source="REDHAT">RHSA-2003:207</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-206.html" source="REDHAT">RHSA-2003:206</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_031_nfs_utils.html" source="SUSE">SuSE-SA:2003:031</ref>
      <ref url="http://www.debian.org/security/2003/dsa-349" source="DEBIAN">DSA-349</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001262.1-1" source="SUNALERT">1001262</ref>
      <ref url="http://securitytracker.com/id?1007187" source="SECTRACK">1007187</ref>
      <ref url="http://secunia.com/advisories/9259" source="SECUNIA">9259</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839032403325&amp;w=2" source="BUGTRAQ" adv="1">20030716 Immunix Secured OS 7+ nfs-utils update -- bugtraq</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820223707191&amp;w=2" source="BUGTRAQ" adv="1">20030714 Linux nfs-utils xlog() off-by-one bug</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html" source="VULNWATCH" adv="1">20030714 Reality of the rpc.mountd bug</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html" source="VULNWATCH" adv="1">20030714 Linux nfs-utils xlog() off-by-one bug</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:076" source="MANDRAKE">MDKSA-2003:076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:443" source="OVAL" sig="1">oval:org.mitre.oval:def:443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3.1" />
        <vers num="0.3.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0253" published="2003-08-18" name="CVE-2003-0253" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-240.html" source="REDHAT" patch="1" adv="1">RHSA-2003:240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" source="MANDRAKE">MDKSA-2003:075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:173" source="OVAL" sig="1">oval:org.mitre.oval:def:173</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0254" published="2003-08-18" name="CVE-2003-0254" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-240.html" source="REDHAT" patch="1" adv="1">RHSA-2003:240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" source="MANDRAKE">MDKSA-2003:075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:183" source="OVAL" sig="1">oval:org.mitre.oval:def:183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0255" published="2003-05-27" name="CVE-2003-0255" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/397604" source="CERT-VN">VU#397604</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-175.html" source="REDHAT" patch="1" adv="1">RHSA-2003:175</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105215110111174&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030504 Key validity bug in GnuPG 1.2.1 and earlier</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11930" source="XF">gnupg-invalid-key-acceptance(11930)</ref>
      <ref url="http://www.securityfocus.com/bid/7497" source="BID">7497</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-176.html" source="REDHAT">RHSA-2003:176</ref>
      <ref url="http://www.osvdb.org/4947" source="OSVDB">4947</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-34.txt" source="TURBO">TLSA200334</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:061" source="MANDRAKE">MDKSA-2003:061</ref>
      <ref url="http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html" source="MISC">http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html" source="ENGARDE">20030515-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362224514081&amp;w=2" source="BUGTRAQ">20030522 [slackware-security]  GnuPG key validation fix (SSA:2003-141-04)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311804129104&amp;w=2" source="BUGTRAQ">20030516 [OpenPKG-SA-2003.029] OpenPKG Security Advisory (gnupg)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301357425157&amp;w=2" source="ENGARDE">ESA-20030515-016</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000694" source="CONECTIVA">CLA-2003:694</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:135" source="OVAL" sig="1">oval:org.mitre.oval:def:135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0256" published="2003-05-27" name="CVE-2003-0256" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:055" source="MANDRAKE">MDKSA-2003:055</ref>
      <ref url="http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2" source="CONFIRM">http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000665" source="CONECTIVA">CLA-2003:665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kopete">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0257" published="2004-04-15" name="CVE-2003-0257" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1" source="IBM" patch="1" adv="1">MSS-OAR-E01-2003:0660.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12000" source="XF" adv="1">aix-print-format-string(12000)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0258" published="2003-05-27" name="CVE-2003-0258" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/727780" source="CERT-VN">VU#727780</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" source="CISCO" patch="1" adv="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11954" source="XF">cisco-vpn-unauth-access(11954)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="3.5(rel)" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.7d" />
        <vers num="4.0" />
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3" />
        <vers num="3.6.5" />
        <vers num="3.6.7" />
        <vers num="3.6.7.a" />
        <vers num="3.6.7.b" />
        <vers num="3.6.7.c" />
        <vers num="3.6.7.d" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0259" published="2003-05-27" name="CVE-2003-0259" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/317348" source="CERT-VN">VU#317348</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" source="CISCO" patch="1" adv="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11955" source="XF">cisco-vpn-ssh-dos(11955)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.0" />
        <vers num="2.5.2.a" />
        <vers num="2.5.2.b" />
        <vers num="2.5.2.c" />
        <vers num="2.5.2.d" />
        <vers num="2.5.2.f" />
        <vers num="3.0" />
        <vers num="3.0.3.a" />
        <vers num="3.0.3.b" />
        <vers num="3.0.4" />
        <vers num="3.1" />
        <vers num="3.1(rel)" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.4" />
        <vers num="3.5(rel)" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.7" />
        <vers num="3.6.7d" />
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3" />
        <vers num="3.6.5" />
        <vers num="3.6.7" />
        <vers num="3.6.7.a" />
        <vers num="3.6.7.b" />
        <vers num="3.6.7.c" />
        <vers num="3.6.7.d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0260" published="2003-05-27" name="CVE-2003-0260" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/221164" source="CERT-VN">VU#221164</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" source="CISCO" patch="1" adv="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11956" source="XF">cisco-vpn-icmp-dos(11956)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.0" />
        <vers num="2.5.2.a" />
        <vers num="2.5.2.b" />
        <vers num="2.5.2.c" />
        <vers num="2.5.2.d" />
        <vers num="2.5.2.f" />
        <vers num="3.0" />
        <vers num="3.0.3.a" />
        <vers num="3.0.3.b" />
        <vers num="3.0.4" />
        <vers num="3.1" />
        <vers num="3.1(rel)" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.4" />
        <vers num="3.5(rel)" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.7" />
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3" />
        <vers num="3.6.5" />
        <vers num="3.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0261" published="2003-05-27" name="CVE-2003-0261" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-302" source="DEBIAN" patch="1" adv="1">DSA-302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuzz" name="fuzz">
        <vers prev="1" num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0262" published="2003-05-27" name="CVE-2003-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-299" source="DEBIAN" patch="1" adv="1">DSA-299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11945" source="XF">kataxwr-gain-privileges(11945)</ref>
      <ref url="http://www.securityfocus.com/bid/7505" source="BID">7505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leksbot" name="leksbot">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0263" published="2003-05-27" name="CVE-2003-0263" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7508" source="BID" patch="1" adv="1">7508</ref>
      <ref url="http://www.securityfocus.com/bid/7506" source="BID" patch="1" adv="1">7506</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105223471822836&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11951" source="XF">ftgate-mailfrom-rcptto-bo(11951)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0052.html" source="VULNWATCH">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="floosietek" name="ftgatepro">
        <vers num="1.22_1328" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0264" published="2003-05-27" name="CVE-2003-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slmail-vulns.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/slmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233360321895&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232506011335&amp;w=2" source="BUGTRAQ">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail">
        <vers num="5.1.0.4420" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0265" published="2003-05-27" name="CVE-2003-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7421" source="BID" patch="1" adv="1">7421</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232424810097&amp;w=2" source="BUGTRAQ">20030507 SAP database local root vulnerability during installation. (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers num="7.3.29" />
        <vers num="7.4.3.7_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0266" published="2003-05-27" name="CVE-2003-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" source="MISC" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2" source="BUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bvrp_software" name="slwebmail">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0267" published="2003-05-27" name="CVE-2003-0267" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" source="MISC" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2" source="BUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bvrp_software" name="slwebmail">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0268" published="2003-05-27" name="CVE-2003-0268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" source="MISC" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2" source="BUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bvrp_software" name="slwebmail">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0269" published="2003-05-27" name="CVE-2003-0269" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7503" source="BID" adv="1">7503</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004892.html" source="FULLDISC">20030506 youbin local root exploit + advisory</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0053.html" source="VULNWATCH">20030506 youbin local root exploit + advisory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11949" source="XF">youbin-home-bo(11949)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105223947528794&amp;w=2" source="BUGTRAQ">20030506 youbin local root exploit + advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youbin" name="youbin">
        <vers num="2.5" />
        <vers num="3.0" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0270" published="2003-06-16" name="CVE-2003-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11980" source="XF">airport-auth-credentials-disclosure(11980)</ref>
      <ref url="http://www.securityfocus.com/bid/7554" source="BID" adv="1">7554</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a051203-1.txt" source="ATSTAKE" adv="1">A051203-1</ref>
      <ref url="http://securitytracker.com/id?1006742" source="SECTRACK">1006742</ref>
      <ref url="http://secunia.com/advisories/8773" source="SECUNIA">8773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="802.11n">
        <vers num="7.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0271" published="2003-05-27" name="CVE-2003-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/316958" source="BUGTRAQ" adv="1">20030331 Personal FTP Server</ref>
      <ref url="http://security.nnov.ru/search/document.asp?docid=4309" source="MISC">http://security.nnov.ru/search/document.asp?docid=4309</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240469318622&amp;w=2" source="BUGTRAQ" adv="1">20030508 Remote Stack Overflow exploit for Personal FTPD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cooolsoft" name="personal_ftp_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0272" published="2003-05-27" name="CVE-2003-0272" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240907024660&amp;w=2" source="BUGTRAQ" patch="1">20030508 miniPortail (PHP) : Admin Access</ref>
      <ref url="http://www.frog-man.org/tutos/miniPortail.txt" source="MISC">http://www.frog-man.org/tutos/miniPortail.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miniportal" name="miniportal">
        <vers num="1.9" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0273" published="2003-05-27" name="CVE-2003-0273" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html" source="CONFIRM" adv="1">http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240947225275&amp;w=2" source="BUGTRAQ">20030508 Fw: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_practical_solutions" name="request_tracker">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0274" published="2003-05-27" name="CVE-2003-0274" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105241224228693&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030508 SRT2003-05-08-1137 - ListProc mailing list ULISTPROC_UMASK overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cren" name="listproc">
        <vers num="8.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0275" published="2003-06-16" name="CVE-2003-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105249980809988&amp;w=2" source="BUGTRAQ">20030509 II-Labs Advisory: Remote code execution in YaBBse 1.5.2 (php version)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.2" edition="" />
        <vers num="1.5.2" edition=":second_edition" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0276" published="2003-06-16" name="CVE-2003-0276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11889" source="XF">pi3web-get-request-bo(11889)</ref>
      <ref url="http://www.securityfocus.com/bid/7555" source="BID">7555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105275789410250&amp;w=2" source="BUGTRAQ">20030512 Unix Version of the Pi3web DoS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155818012718&amp;w=2" source="BUGTRAQ">20030428 Pi3Web 2.0.1 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pi3" name="pi3web">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0277" published="2003-06-16" name="CVE-2003-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11987" source="XF">happymall-dotdot-directory-traversal(11987)</ref>
      <ref url="http://www.securityfocus.com/bid/7559" source="BID">7559</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276130814262&amp;w=2" source="BUGTRAQ">20030512 One more flaw in Happymall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="happycgi" name="happymall">
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0278" published="2003-06-16" name="CVE-2003-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276130814262&amp;w=2" source="BUGTRAQ">20030512 One more flaw in Happymall</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11988" source="XF">happymall-normalhtml-xss(11988)</ref>
      <ref url="http://www.securityfocus.com/bid/7557" source="BID">7557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="happycgi.com" name="happymall">
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0279" published="2003-06-16" name="CVE-2003-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11984" source="XF">phpnuke-web-sql-injection(11984)</ref>
      <ref url="http://www.securityfocus.com/bid/7558" source="BID">7558</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276019312980&amp;w=2" source="BUGTRAQ" adv="1">20030512 Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</ref>
      <ref url="http://www.securityfocus.com/bid/7588" source="BID">7588</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html" source="BUGTRAQ">20030513 More and More SQL injection on PHP-Nuke 6.5.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0280" published="2003-06-16" name="CVE-2003-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105258772101349&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11975" source="XF">cmailserver-smtp-bo(11975)</ref>
      <ref url="http://www.securityfocus.com/bid/7548" source="BID">7548</ref>
      <ref url="http://www.securityfocus.com/bid/7547" source="BID">7547</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html" source="VULNWATCH">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youngzsoft" name="cmailserver">
        <vers num="4.0.2003.23.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0281" published="2003-06-16" name="CVE-2003-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11977" source="XF">firebird-interbase-bo(11977)</ref>
      <ref url="http://www.securityfocus.com/bid/7546" source="BID">7546</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-18.xml" source="GENTOO">GLSA-200405-18</ref>
      <ref url="http://secunia.com/advisories/8758" source="SECUNIA">8758</ref>
      <ref url="http://seclists.org/lists/bugtraq/2002/Jun/0212.html" source="BUGTRAQ">20020617 Interbase 6.0 malloc() issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259012802997&amp;w=2" source="BUGTRAQ" adv="1">20030509 Firebird Local exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0282" published="2003-06-16" name="CVE-2003-0282" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7550" source="BID" patch="1" adv="1">7550</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-199.html" source="REDHAT" patch="1" adv="1">RHSA-2003:199</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-42.txt" source="TURBO">TLSA-2003-42</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-200.html" source="REDHAT">RHSA-2003:200</ref>
      <ref url="http://www.debian.org/security/2003/dsa-344" source="DEBIAN">DSA-344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259038503175&amp;w=2" source="BUGTRAQ" adv="1">20030509 unzip directory traversal revisited</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01" source="IMMUNIX">IMNX-2003-7+-017-01</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt" source="SCO">CSSA-2003-031.0</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt" source="CALDERA">CSSA-2003-031.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12004" source="XF">unzip-dotdot-directory-traversal(12004)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:073" source="MANDRAKE">MDKSA-2003:073</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-111.shtml" source="CIAC">N-111</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105786446329347&amp;w=2" source="BUGTRAQ">20030710 [OpenPKG-SA-2003.033] OpenPKG Security Advisory (infozip)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000672" source="CONECTIVA">CLA-2003:672</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:619" source="OVAL" sig="1">oval:org.mitre.oval:def:619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info-zip" name="unzip">
        <vers num="5.50" />
      </prod>
      <prod vendor="sco" name="openlinux_server">
        <vers num="3.1.1" />
      </prod>
      <prod vendor="sco" name="openlinux_workstation">
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0283" published="2003-06-16" name="CVE-2003-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "&lt;&lt;" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11974" source="XF">phorum-message-html-injection(11974)</ref>
      <ref url="http://www.securityfocus.com/bid/7545" source="BID">7545</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105251421925394&amp;w=2" source="BUGTRAQ">20030509 Re: A Phorum's bug...</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105251043821533&amp;w=2" source="BUGTRAQ">20030509 A Phorum's bug...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0284" published="2003-06-16" name="CVE-2003-0284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/184820" source="CERT-VN" patch="1" adv="1">VU#184820</ref>
      <ref url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0285" published="2003-06-16" name="CVE-2003-0285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/814617" source="CERT-VN">VU#814617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11993" source="XF">aix-sendmail-mail-relay(11993)</ref>
      <ref url="http://www.securityfocus.com/bid/7580" source="BID">7580</ref>
      <ref url="http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt" source="MISC" adv="1">http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284689228961&amp;w=2" source="BUGTRAQ" adv="1">20030513 AIX sendmail open relay</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers prev="1" num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0286" published="2003-06-16" name="CVE-2003-0286" modified="2009-07-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7549" source="BID" patch="1">7549</ref>
      <ref url="http://www.securityfocus.com/bid/35764" source="BID" patch="1">35764</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11981" source="XF">snitz-register-sql-injection(11981)</ref>
      <ref url="http://secunia.com/advisories/35733" source="SECUNIA" adv="1">35733</ref>
      <ref url="http://packetstormsecurity.org/0305-exploits/snitz_exec.txt" source="MISC">http://packetstormsecurity.org/0305-exploits/snitz_exec.txt</ref>
      <ref url="http://osvdb.org/56166" source="OSVDB">56166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105277599131134&amp;w=2" source="BUGTRAQ">20030513 Snitz Forum 3.3.03 Remote Command Execution</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html" source="VULNWATCH">20030512 Snitz Forum 3.3.03 Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers prev="1" num="3.3.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0287" published="2003-06-16" name="CVE-2003-0287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105277690132079&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030512 Re: CSS found in Movable Type</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276879622636&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030512 CSS found in Movable Type</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284589927655&amp;w=2" source="BUGTRAQ" adv="1">20030513 Re: CSS found in Movable Type -- Nope</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12003" source="XF">movable-type-comment-xss(12003)</ref>
      <ref url="http://www.securityfocus.com/bid/7560" source="BID">7560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="six_apart" name="movable_type">
        <vers prev="1" num="2.6" />
        <vers num="2.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0288" published="2003-06-16" name="CVE-2003-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the file &amp; folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/64_e.html" source="MISC" patch="1" adv="1">http://www.lac.co.jp/security/english/snsadv_e/64_e.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105283843417610&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 [SNS Advisory No.64] IP Messenger for Win Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11986" source="XF">ip-messenger-filename-bo(11986)</ref>
      <ref url="http://www.securityfocus.com/bid/7566" source="BID">7566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hiroaki_shirouzu" name="ip_messenger">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0289" published="2003-06-16" name="CVE-2003-0289" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7565" source="BID" patch="1" adv="1">7565</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105285564307225&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 cdrtools2.0 Format String Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105286031812533&amp;w=2" source="BUGTRAQ">20030513 Cdrecord_local_root_exploit.</ref>
      <ref url="ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz" source="CONFIRM">ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12007" source="XF">cdrtools-scsiopen-format-string(12007)</ref>
      <ref url="http://www.securiteam.com/exploits/5ZP0C2AAAC.html" source="MISC">http://www.securiteam.com/exploits/5ZP0C2AAAC.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:058" source="MANDRAKE">MDKSA-2003:058</ref>
      <ref url="http://forums.gentoo.org/viewtopic.php?t=54904" source="GENTOO">200305-06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdrtools" name="cdrecord">
        <vers num="1.11" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0290" published="2003-06-16" name="CVE-2003-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284631428187&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 eServ Memory Leak Solution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284630228137&amp;w=2" source="BUGTRAQ" adv="1">20030511 eServ Memory Leak Enables Denial of Service Attacks</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11973" source="XF">eserv-multiple-connections-dos(11973)</ref>
      <ref url="http://www.securityfocus.com/bid/7552" source="BID">7552</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0064.html" source="VULNWATCH">20030511 eServ Memory Leak Enables Denial of Service Attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etype" name="eserv">
        <vers num="2.9x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0291" published="2003-06-16" name="CVE-2003-0291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm" source="MISC" patch="1" adv="1">http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105292451702516&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030514 Memory leak in 3COM 812 DSL routers</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301488426951&amp;w=2" source="BUGTRAQ" adv="1">20030515 RE : Memory leak in 3COM DSL routers</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11999" source="XF">3com-officeconnect-memory-leak(11999)</ref>
      <ref url="http://www.securityfocus.com/bid/7592" source="BID">7592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cp4144">
        <vers num="1.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0292" published="2003-06-16" name="CVE-2003-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7596" source="BID">7596</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105292750807005&amp;w=2" source="BUGTRAQ">20030514 Inktomi Traffic-Server XSS: man-in-the-middle XSS !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inktomi" name="inktomi_traffic-server">
        <vers num="5.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0293" published="2003-06-16" name="CVE-2003-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105293128612131&amp;w=2" source="BUGTRAQ" adv="1">20030514 PalmOS ICMP flood DoS.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palm" name="palmos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0294" published="2003-06-16" name="CVE-2003-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105293834421549&amp;w=2" source="BUGTRAQ">20030514 php-proxima Remote File Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-proxima" name="php-proxima">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0295" published="2003-06-16" name="CVE-2003-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105292832607981&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030514 VBulletin Preview Message - XSS Vuln</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105293890422210&amp;w=2" source="BUGTRAQ" adv="1">20030514 Re: VBulletin Preview Message - XSS Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0296" published="2003-06-16" name="CVE-2003-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0297" published="2003-06-16" name="CVE-2003-0297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-114.html" source="REDHAT">RHSA-2005:114</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-015.html" source="REDHAT">RHSA-2005:015</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430302/100/0/threaded" source="FEDORA">FLSA:184074</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="c-client">
        <vers num="" />
      </prod>
      <prod vendor="university_of_washington" name="imap-2002b">
        <vers num="" />
      </prod>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0298" published="2003-06-16" name="CVE-2003-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0299" published="2003-06-16" name="CVE-2003-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.4.1" />
      </prod>
      <prod vendor="stuart_parmenter" name="balsa">
        <vers num="2.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0300" published="2003-06-16" name="CVE-2003-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.00.2800.1106" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
      </prod>
      <prod vendor="mutt" name="mutt">
        <vers num="1.4.1" />
      </prod>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1" />
      </prod>
      <prod vendor="stuart_parmenter" name="balsa">
        <vers num="2.0.10" />
      </prod>
      <prod vendor="sylpheed" name="sylpheed_email_client">
        <vers num="0.8.11" />
      </prod>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.53" />
      </prod>
      <prod vendor="ximian" name="evolution">
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0301" published="2003-06-16" name="CVE-2003-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.00.2800.1106" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0302" published="2003-06-16" name="CVE-2003-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0303" published="2003-06-09" name="CVE-2003-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105302025601231&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" source="VULNWATCH" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref url="http://www.securityfocus.com/bid/7609" source="BID">7609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneorzero" name="oneorzero_helpdesk">
        <vers num="1.4_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0304" published="2003-06-09" name="CVE-2003-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105302025601231&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" source="VULNWATCH" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneorzero" name="oneorzero_helpdesk">
        <vers num="1.4_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0305" published="2003-06-09" name="CVE-2003-0305" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030515-saa.shtml" source="CISCO" patch="1" adv="1">20030515 Cisco Security Advisory: Cisco IOS Software Processing of SAA Packets</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5608" source="OVAL">oval:org.mitre.oval:def:5608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(15)s" />
        <vers num="12.0(15)sc" />
        <vers num="12.0(15)sl" />
        <vers num="12.0(16)s" />
        <vers num="12.0(16)sc" />
        <vers num="12.0(16)st" />
        <vers num="12.0(17)s" />
        <vers num="12.0(17)sl" />
        <vers num="12.0(18)s" />
        <vers num="12.0(18)sl" />
        <vers num="12.0(19)s" />
        <vers num="12.0(19)sl" />
        <vers num="12.0(19)sp" />
        <vers num="12.0(20)sl" />
        <vers num="12.0(20)sp" />
        <vers num="12.0(21)s" />
        <vers num="12.0(21)sl" />
        <vers num="12.0(21)sx" />
        <vers num="12.1(10)" />
        <vers num="12.1(10)e" />
        <vers num="12.1(10)ec" />
        <vers num="12.1(10)ex" />
        <vers num="12.1(10)ey" />
        <vers num="12.1(10.5)ec" />
        <vers num="12.1(10a)" />
        <vers num="12.1(11)" />
        <vers num="12.1(11.5)e" />
        <vers num="12.1(11a)" />
        <vers num="12.1(11b)" />
        <vers num="12.1(11b)e" />
        <vers num="12.1(12)" />
        <vers num="12.1(12a)" />
        <vers num="12.1(12b)" />
        <vers num="12.1(12c)" />
        <vers num="12.1(13)" />
        <vers num="12.1(14)" />
        <vers num="12.1(14.5)" />
        <vers num="12.1(8)ea" />
        <vers num="12.1(9)ea" />
        <vers num="12.2(10.5)s" />
        <vers num="12.2(6.8a)" />
        <vers num="12.2(7)" />
        <vers num="12.2(7)da" />
        <vers num="12.2(7a)" />
        <vers num="12.2(7b)" />
        <vers num="12.2(7c)" />
        <vers num="12.2(9)s" />
        <vers num="12.2(9.4)da" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0306" published="2003-06-09" name="CVE-2003-0306" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-027.asp" source="MS">MS03-027</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=105241032526289&amp;w=2" source="VULN-DEV" adv="1">20030507 Buffer overflow in Explorer.exe</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301349925036&amp;w=2" source="BUGTRAQ" adv="1">20030515 Re[2]: EXPLOIT: Buffer overflow in Explorer.exe on Windows XP SP1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284486526310&amp;w=2" source="BUGTRAQ" adv="1">20030511 Detailed analysis: Buffer overflow in Explorer.exe on Windows XP SP1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3095" source="OVAL" sig="1">oval:org.mitre.oval:def:3095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0307" published="2003-06-09" name="CVE-2003-0307" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105295155004969&amp;w=2" source="BUGTRAQ" adv="1">20030514 [VULNERABILITY] PHP 'poster version.two'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poster" name="poster">
        <vers num="version.two" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0308" published="2003-05-15" name="CVE-2003-0308" modified="2008-11-11" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-305" source="DEBIAN" patch="1">DSA-305</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=235770" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=235770</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2008/10/30/2" source="MLIST">[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire</ref>
      <ref url="http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base" source="CONFIRM">http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base</ref>
      <ref url="http://bugs.debian.org/496408" source="CONFIRM">http://bugs.debian.org/496408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.12.3" />
        <vers num="8.12.9" />
        <vers num="8.9.3" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0309" published="2003-06-09" name="CVE-2003-0309" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/251788" source="CERT-VN">VU#251788</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12019" source="XF">ie-frame-restrictions-bypass(12019)</ref>
      <ref url="http://www.securityfocus.com/bid/7539" source="BID">7539</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-020.asp" source="MS">MS03-020</ref>
      <ref url="http://secunia.com/advisories/8807" source="SECUNIA">8807</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105294162726096&amp;w=2" source="NTBUGTRAQ" adv="1">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105294162726096&amp;w=2" source="NTBUGTRAQ">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294081325040&amp;w=2" source="BUGTRAQ" adv="1">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105249399103214&amp;w=2" source="BUGTRAQ" adv="1">20030508 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! [CRITICAL]</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:948" source="OVAL" sig="1">oval:org.mitre.oval:def:948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0310" published="2003-06-16" name="CVE-2003-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105310013606680&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030516 EzPublish Directory XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ez_publish" name="ez_publish">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0312" published="2003-06-16" name="CVE-2003-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0313" published="2003-06-16" name="CVE-2003-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0314" published="2003-06-16" name="CVE-2003-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "&lt;/" sequence.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0315" published="2003-06-16" name="CVE-2003-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0316" published="2003-06-16" name="CVE-2003-0316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm" source="MISC" patch="1">http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0188.html" source="BUGTRAQ" patch="1" adv="1">20030516 Venturi Client 2.1 confirmed as open relay [Verizon Wireless Mobile Office]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fourelle_venturi_wireless" name="venturi_client">
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0317" published="2003-12-31" name="CVE-2003-0317" modified="2008-10-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=25" source="IDEFENSE">20030522 Authentication Bypass in iisPROTECT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iisprotect" name="iisprotect">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0318" published="2003-06-09" name="CVE-2003-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105319538308834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030517 PHP-Nuke code injection in Yearly Stats at Statistics module</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0319" published="2003-06-09" name="CVE-2003-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105319299407291&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030517 Buffer overflow vulnerability found in MailMax version 5</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0072.html" source="VULNWATCH" patch="1" adv="1">20030517 Buffer overflow vulnerability found in MailMax version 5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartmax_software" name="mailmax">
        <vers prev="1" num="5.0.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0320" published="2003-06-09" name="CVE-2003-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105320172212990&amp;w=2" source="BUGTRAQ" adv="1">20030517 Remote code execution in ttCMS &lt;=v2.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andy_prevost" name="ttcms">
        <vers prev="1" num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0321" published="2003-06-09" name="CVE-2003-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled by the functions (1) send_ctcp, (2) cannot_join_channel, (3) cluster, (4) BX_compress_modes, (5) handle_oper_vision, and (6) ban_it.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-306" source="DEBIAN" patch="1" adv="1">DSA-306</ref>
      <ref url="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" source="MISC" patch="1">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852615211913&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030324 GLSA:  bitchx (200303-21)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766521328322&amp;w=2" source="BUGTRAQ" adv="1">20030313 Buffer overflows in ircII-based clients</ref>
      <ref url="http://www.securityfocus.com/bid/7100" source="BID">7100</ref>
      <ref url="http://www.securityfocus.com/bid/7099" source="BID">7099</ref>
      <ref url="http://www.securityfocus.com/bid/7097" source="BID">7097</ref>
      <ref url="http://www.securityfocus.com/bid/7096" source="BID">7096</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" source="CONECTIVA">CLA-2003:655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers prev="1" num="1.0.0c19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0322" published="2003-06-09" name="CVE-2003-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-306" source="DEBIAN" patch="1" adv="1">DSA-306</ref>
      <ref url="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" source="MISC" patch="1">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers prev="1" num="1.0.0c19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0323" published="2003-06-09" name="CVE-2003-0323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-291" source="DEBIAN" patch="1" adv="1">DSA-291</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104808915402926&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 [OpenPKG-SA-2003.024] OpenPKG Security Advisory (ircii)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766521328322&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030313 Buffer overflows in ircII-based clients</ref>
      <ref url="http://www.debian.org/security/2003/dsa-298" source="DEBIAN">DSA-298</ref>
      <ref url="http://www.securityfocus.com/bid/7098" source="BID">7098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_sandrof" name="ircii">
        <vers num="2002-09-12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0324" published="2003-06-09" name="CVE-2003-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-287" source="DEBIAN" patch="1" adv="1">DSA-287</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766521328322&amp;w=2" source="BUGTRAQ" adv="1">20030313 Buffer overflows in ircII-based clients</ref>
      <ref url="http://www.securityfocus.com/bid/7091" source="BID">7091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic" name="epic4">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0325" published="2003-06-09" name="CVE-2003-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105346309123217&amp;w=2" source="BUGTRAQ" adv="1">20030520 Maelstrom Local Buffer Overflow Exploit, FreeBSD 4.8 edition</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105344501331344&amp;w=2" source="BUGTRAQ" adv="1">20030519 Maelstrom exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105337792703887&amp;w=2" source="BUGTRAQ" adv="1">20030518 Maelstrom Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ambrosia_software" name="maelstrom">
        <vers prev="1" num="3.0.5" />
        <vers num="3.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0326" published="2003-06-09" name="CVE-2003-0326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105337692202626&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030519 bazarr slocate</ref>
      <ref url="http://www.securityfocus.com/bid/7629" source="BID">7629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0327" published="2003-12-15" name="CVE-2003-0327" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0016.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0016.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13800" source="XF">sybase-passwordarray-bo(13800)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106936096103805&amp;w=2" source="BUGTRAQ">20031120 R7-0016: Sybase ASE 12.5 Remote Password Array Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="adaptive_server_enterprise">
        <vers num="12.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0328" published="2003-06-09" name="CVE-2003-0328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1" source="CONFIRM" patch="1" adv="1">ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-342.html" source="REDHAT">RHSA-2003:342</ref>
      <ref url="http://www.debian.org/security/2003/dsa-399" source="DEBIAN">DSA-399</ref>
      <ref url="http://www.debian.org/security/2003/dsa-306" source="DEBIAN">DSA-306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic" name="epic4">
        <vers num="pre2.002" />
        <vers num="pre2.003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0329" published="2003-06-09" name="CVE-2003-0329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105344578100315&amp;w=2" source="BUGTRAQ" adv="1">20030520 Plaintext Password in Settings.ini of CesarFTP</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0074.html" source="VULNWATCH" adv="1">20030520 Plaintext Password in Settings.ini of CesarFTP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aclogic" name="cesarftp">
        <vers num="0.99g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0330" published="2003-06-09" name="CVE-2003-0330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105344891005369&amp;w=2" source="BUGTRAQ">20030520 Maelstrom Local Buffer Overflow Exploit</ref>
      <ref url="http://www.securitytracker.com/id?1008832" source="SECTRACK">1008832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ambrosia_software" name="maelstrom">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0331" published="2003-06-09" name="CVE-2003-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105345273210334&amp;w=2" source="BUGTRAQ" adv="1">20030520 More vulnerabilities in ttForum/ttCMS -> SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ttcms" name="ttforum">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0332" published="2003-06-09" name="CVE-2003-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html" source="VULNWATCH" patch="1" adv="1">20030520 BadBlue Remote Administrative Interface Access Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105346382524169&amp;w=2" source="BUGTRAQ">20030520 BadBlue Remote Administrative Interface Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="working_resources_inc." name="badblue">
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0333" published="2003-05-19" name="CVE-2003-0333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/971364" source="CERT-VN" adv="1">VU#971364</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105190667523456&amp;w=2" source="BUGTRAQ" patch="1">20030502 Re: from bugtraq: HP-UX 11.0 /usr/bin/kermit (fwd)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11929" source="XF" adv="1">hp-ckermit-bo(11929)</ref>
      <ref url="http://www.securityfocus.com/bid/7627" source="BID" adv="1">7627</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105189670912220&amp;w=2" source="BUGTRAQ" adv="1">20030502 HP-UX 11.0 /usr/bin/kermit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0334" published="2003-05-10" name="CVE-2003-0334" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259643606984&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030510 BitchX: Crash when channel modes change</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" source="CONECTIVA" patch="1" adv="1">CLA-2003:655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12008" source="XF">bitchx-mode-change-dos(12008)</ref>
      <ref url="http://www.securityfocus.com/bid/7551" source="BID">7551</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:069" source="MANDRAKE">MDKSA-2003:069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers prev="1" num="1.0c20cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0335" published="2003-05-22" name="CVE-2003-0335" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105361968110719&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030522 [slackware-security]  quotacheck security fix in rc.M (SSA:2003-141-06)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0336" published="2003-05-22" name="CVE-2003-0336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly handled by Eudora.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362278914731&amp;w=2" source="BUGTRAQ" adv="1">20030522 Eudora 5.2.1 attachment spoof</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0337" published="2003-05-22" name="CVE-2003-0337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105361879109409&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030522 Security advisory: LSF 5.1 local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platform" name="lsadmin">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0338" published="2003-05-21" name="CVE-2003-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353168619211&amp;w=2" source="BUGTRAQ" adv="1">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0077.html" source="VULNWATCH" adv="1">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wsmp3" name="wsmp3_daemon">
        <vers num="0.0.10" />
        <vers num="0.0.8" />
        <vers num="0.0.9" />
      </prod>
      <prod vendor="wsmp3" name="wsmp3_web_server">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0339" published="2003-05-22" name="CVE-2003-0339" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105361764807746&amp;w=2" source="BUGTRAQ" adv="1">20030522 WsMp3d remote exploit.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353178019353&amp;w=2" source="BUGTRAQ">20030521 Remote Heap Corruption Overflow vulnerability in WsMp3d.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353178019353&amp;w=2" source="VULNWATCH">20030521 Remote Heap Corruption Overflow vulnerability in WsMp3d.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wsmp3" name="wsmp3_daemon">
        <vers num="0.0.10" />
        <vers num="0.0.8" />
        <vers num="0.0.9" />
      </prod>
      <prod vendor="wsmp3" name="wsmp3_web_server">
        <vers num="0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0340" published="2003-05-21" name="CVE-2003-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0230.html" source="BUGTRAQ" adv="1">20030521 Demarc Puresecure v1.6 - Plaintext password issue -</ref>
    </refs>
    <vuln_soft>
      <prod vendor="demarc_security" name="puresecure">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0341" published="2003-05-21" name="CVE-2003-0341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353266220520&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030521 [AP] Owl Intranet Engine CSS Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.7" />
        <vers num="0.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0342" published="2003-05-20" name="CVE-2003-0342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353283720837&amp;w=2" source="BUGTRAQ" adv="1">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="selom_ofori" name="blackmoon_ftp_server">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0343" published="2003-05-21" name="CVE-2003-0343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353283720837&amp;w=2" source="BUGTRAQ" adv="1">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="selom_ofori" name="blackmoon_ftp_server">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0344" published="2003-06-16" name="CVE-2003-0344" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/679556" source="CERT-VN">VU#679556</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-020.asp" source="MS" patch="1" adv="1">MS03-020</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20030604.html" source="EEYE" patch="1" adv="1">AD20030604</ref>
      <ref url="http://secunia.com/advisories/8943" source="SECUNIA">8943</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006401.html" source="FULLDISC">20030709 IE Object Type Overflow Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105476381609135&amp;w=2" source="BUGTRAQ">20030604 Internet Explorer Object Type Property Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:922" source="OVAL" sig="1">oval:org.mitre.oval:def:922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows_server_2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0345" published="2003-08-18" name="CVE-2003-0345" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337764" source="CERT-VN">VU#337764</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12544" source="XF" patch="1" adv="1">win-smb-bo(12544)</ref>
      <ref url="http://www.securityfocus.com/bid/8152" source="BID" patch="1" adv="1">8152</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-024.asp" source="MS" patch="1" adv="1">MS03-024</ref>
      <ref url="http://securitytracker.com/id?1007154" source="SECTRACK">1007154</ref>
      <ref url="http://secunia.com/advisories/9225" source="SECUNIA">9225</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3391" source="OVAL" sig="1">oval:org.mitre.oval:def:3391</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:146" source="OVAL" sig="1">oval:org.mitre.oval:def:146</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:118" source="OVAL" sig="1">oval:org.mitre.oval:def:118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":terminal_server_alpha" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0346" published="2003-08-27" name="CVE-2003-0346" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-18.html" source="CERT" patch="1" adv="1">CA-2003-18</ref>
      <ref url="http://www.kb.cert.org/vuls/id/561284" source="CERT-VN">VU#561284</ref>
      <ref url="http://www.kb.cert.org/vuls/id/265232" source="CERT-VN">VU#265232</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-030.asp" source="MS" patch="1" adv="1">MS03-030</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105899759824008&amp;w=2" source="BUGTRAQ" adv="1">20030723 EEYE: Windows MIDI Decoder (QUARTZ.DLL) Heap Corruption</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:218" source="OVAL" sig="1">oval:org.mitre.oval:def:218</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1104" source="OVAL" sig="1">oval:org.mitre.oval:def:1104</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1095" source="OVAL" sig="1">oval:org.mitre.oval:def:1095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="5.2" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.0a" />
        <vers num="8.1" />
        <vers num="9.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0347" published="2003-10-20" name="CVE-2003-0347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/804780" source="CERT-VN">VU#804780</ref>
      <ref url="http://www.securityfocus.com/bid/8534" source="BID" patch="1" adv="1">8534</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-037.asp" source="MS" patch="1" adv="1">MS03-037</ref>
      <ref url="http://secunia.com/advisories/9666" source="SECUNIA">9666</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106262077829157&amp;w=2" source="BUGTRAQ" adv="1">20030903 EEYE: VBE Document Property Buffer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.html" source="VULNWATCH">20030903 EEYE: VBE Document Property Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="xp" edition="sp1" />
        <vers num="xp" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2000" />
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":professional" />
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":sdk" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":sdk" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":sdk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0348" published="2003-07-24" name="CVE-2003-0348" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/320516" source="CERT-VN">VU#320516</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-021.asp" source="MS" patch="1" adv="1">MS03-021</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12440" source="XF">mediaplayer-activex-obtain-information(12440)</ref>
      <ref url="http://www.securityfocus.com/bid/8034" source="BID">8034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0349" published="2003-07-24" name="CVE-2003-0349" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/113716" source="CERT-VN">VU#113716</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0306&amp;L=NTBUGTRAQ&amp;P=R4563" source="NTBUGTRAQ" patch="1" adv="1">20030626 Windows Media Services Remote Command Execution #2</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-022.asp" source="MS" patch="1" adv="1">MS03-022</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105665030925504&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030626 Windows Media Services Remote Command Execution #2</ref>
      <ref url="http://securitytracker.com/id?1007059" source="SECTRACK">1007059</ref>
      <ref url="http://secunia.com/advisories/9115" source="SECUNIA">9115</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:938" source="OVAL" sig="1">oval:org.mitre.oval:def:938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0350" published="2003-08-18" name="CVE-2003-0350" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ngssoftware.com/advisories/utilitymanager.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/utilitymanager.txt</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-025.asp" source="MS" patch="1" adv="1">MS03-025</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105777681615939&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 Microsoft Utility Manager Local Privilege Escalation</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0015.html" source="VULNWATCH" patch="1" adv="1">20030709 Microsoft Utility Manager Local Privilege Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12543" source="XF">win2k-accessibility-gain-privileges</ref>
      <ref url="http://www.securityfocus.com/bid/8154" source="BID">8154</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:451" source="OVAL" sig="1">oval:org.mitre.oval:def:451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0351" reject="1" published="2003-12-31" name="CVE-2003-0351" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0306.  Reason: This candidate is a reservation duplicate of CVE-2003-0306.  Notes: All CVE users should reference CVE-2003-0306 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0352" published="2003-08-18" name="CVE-2003-0352" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/568148" source="CERT-VN">VU#568148</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-19.html" source="CERT">CA-2003-19</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-16.html" source="CERT">CA-2003-16</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12629" source="XF" patch="1" adv="1">win-rpc-dcom-bo(12629)</ref>
      <ref url="http://www.securityfocus.com/bid/8205" source="BID" patch="1" adv="1">8205</ref>
      <ref url="http://www.xfocus.org/documents/200307/2.html" source="MISC">http://www.xfocus.org/documents/200307/2.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-026.asp" source="MS">MS03-026</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007357.html" source="FULLDISC">20030730 rpcdcom Universal offsets</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007079.html" source="FULLDISC">20030726 Re: The French BUGTRAQ (New Win RPC Exploit)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105914789527294&amp;w=2" source="BUGTRAQ">20030725 The  Analysis  of LSD's Buffer Overrun in Windows RPC Interface(code revised )</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838687731618&amp;w=2" source="BUGTRAQ">20030716 [LSD] Critical security vulnerability in Microsoft Operating Systems</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:296" source="OVAL" sig="1">oval:org.mitre.oval:def:296</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2343" source="OVAL" sig="1">oval:org.mitre.oval:def:2343</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:194" source="OVAL" sig="1">oval:org.mitre.oval:def:194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0353" published="2003-08-27" name="CVE-2003-0353" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-033.asp" source="MS" patch="1" adv="1">MS03-033</ref>
      <ref url="http://www.securityfocus.com/bid/8455" source="BID">8455</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6954" source="OVAL">oval:org.mitre.oval:def:6954</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106251069107953&amp;w=2" source="NTBUGTRAQ">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106149556627778&amp;w=2" source="BUGTRAQ">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:962" source="OVAL" sig="1">oval:org.mitre.oval:def:962</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:961" source="OVAL" sig="1">oval:org.mitre.oval:def:961</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1039" source="OVAL" sig="1">oval:org.mitre.oval:def:1039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.1.3711.11" edition="ga" />
        <vers num="2.12.4202.3" />
        <vers num="2.5" edition="gold" />
        <vers num="2.5" edition="sp1" />
        <vers num="2.5" edition="sp2" />
        <vers num="2.6" edition="gold" />
        <vers num="2.6" edition="sp1" />
        <vers num="2.6" edition="sp2" />
        <vers num="2.7" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0354" published="2003-06-16" name="CVE-2003-0354" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-181.html" source="REDHAT" patch="1" adv="1">RHSA-2003:181</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-182.html" source="REDHAT">RHSA-2003:182</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:065" source="MANDRAKE">MDKSA-2003:065</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105465818929172&amp;w=2" source="BUGTRAQ">20030603 [OpenPKG-SA-2003.030] OpenPKG Security Advisory (ghostscript)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:133" source="OVAL" sig="1">oval:org.mitre.oval:def:133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0355" published="2003-06-09" name="CVE-2003-0355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/320707" source="BUGTRAQ">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0356" published="2003-06-09" name="CVE-2003-0356" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/641013" source="CERT-VN">VU#641013</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00009.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00009.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-313" source="DEBIAN" patch="1" adv="1">DSA-313</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067" source="MANDRAKE">MDKSA-2003:067</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:69" source="OVAL" sig="1">oval:org.mitre.oval:def:69</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0357" published="2003-06-09" name="CVE-2003-0357" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/361700" source="CERT-VN">VU#361700</ref>
      <ref url="http://www.kb.cert.org/vuls/id/232164" source="CERT-VN">VU#232164</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00009.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00009.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-313" source="DEBIAN" patch="1" adv="1">DSA-313</ref>
      <ref url="http://www.securityfocus.com/bid/7495" source="BID">7495</ref>
      <ref url="http://www.securityfocus.com/bid/7494" source="BID">7494</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067" source="MANDRAKE">MDKSA-2003:067</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:73" source="OVAL" sig="1">oval:org.mitre.oval:def:73</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0358" published="2003-06-09" name="CVE-2003-0358" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/311172/2003-02-08/2003-02-14/0" source="BUGTRAQ">20030209 #!ICadv-02.09.03: nethack 3.4.0 local buffer overflow</ref>
      <ref url="http://www.debian.org/security/2003/dsa-350" source="DEBIAN">DSA-350</ref>
      <ref url="http://www.debian.org/security/2003/dsa-316" source="DEBIAN">DSA-316</ref>
      <ref url="http://nethack.sourceforge.net/v340/bugmore/secpatch.txt" source="CONFIRM">http://nethack.sourceforge.net/v340/bugmore/secpatch.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11283" source="XF">nethack-s-command-bo(11283)</ref>
      <ref url="http://www.securityfocus.com/bid/6806" source="BID">6806</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0359" published="2003-07-24" name="CVE-2003-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-316" source="DEBIAN" patch="1" adv="1">DSA-316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stichting_mathematisch_centrum" name="nethack">
        <vers num="3.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0360" published="2003-06-09" name="CVE-2003-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-307" source="DEBIAN" patch="1" adv="1">DSA-307</ref>
      <ref url="http://gps.seul.org/changelog.html" source="CONFIRM" patch="1">http://gps.seul.org/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.9.1" edition="" />
        <vers num="0.9.1" edition=":woody_gps_package" />
        <vers num="0.9.2" edition="" />
        <vers num="0.9.2" edition=":woody_gps_package" />
        <vers num="0.9.3" edition="" />
        <vers num="0.9.3" edition=":woody_gps_package" />
        <vers num="0.9.4" edition="" />
        <vers num="0.9.4" edition=":woody_gps_package" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0361" published="2003-06-09" name="CVE-2003-0361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-307" source="DEBIAN" patch="1" adv="1">DSA-307</ref>
      <ref url="http://gps.seul.org/changelog.html" source="CONFIRM" patch="1">http://gps.seul.org/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.9.1" edition="" />
        <vers num="0.9.1" edition=":woody_gps_package" />
        <vers num="0.9.2" edition="" />
        <vers num="0.9.2" edition=":woody_gps_package" />
        <vers num="0.9.3" edition="" />
        <vers num="0.9.3" edition=":woody_gps_package" />
        <vers num="0.9.4" edition="" />
        <vers num="0.9.4" edition=":woody_gps_package" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0362" published="2003-06-09" name="CVE-2003-0362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-307" source="DEBIAN">DSA-307</ref>
      <ref url="http://gps.seul.org/changelog.html" source="CONFIRM">http://gps.seul.org/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.9.1" edition="" />
        <vers num="0.9.1" edition=":woody_gps_package" />
        <vers num="0.9.2" edition="" />
        <vers num="0.9.2" edition=":woody_gps_package" />
        <vers num="0.9.3" edition="" />
        <vers num="0.9.3" edition=":woody_gps_package" />
        <vers num="0.9.4" edition="" />
        <vers num="0.9.4" edition=":woody_gps_package" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0363" published="2003-12-31" name="CVE-2003-0363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf" source="MISC" adv="1">http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="licq" name="licq">
        <vers num="1.0.3" />
        <vers num="1.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0364" published="2003-06-16" name="CVE-2003-0364" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-187.html" source="REDHAT" patch="1" adv="1">RHSA-2003:187</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO" adv="1">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-195.html" source="REDHAT">RHSA-2003:195</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:295" source="OVAL" sig="1">oval:org.mitre.oval:def:295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0365" published="2003-06-16" name="CVE-2003-0365" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables with malicious programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427404625027&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030529 ICQLite executable trojaning</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icq_inc" name="icqlite">
        <vers num="2003a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0366" published="2003-07-24" name="CVE-2003-0366" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-318" source="DEBIAN" patch="1" adv="1">DSA-318</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lysator" name="lyskom-server">
        <vers prev="1" num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0367" published="2003-07-02" name="CVE-2003-0367" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-38.txt" source="TURBO" patch="1" adv="1">TLSA-2003-38</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html" source="CONFIRM" patch="1" adv="1">http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-308" source="DEBIAN" patch="1" adv="1">DSA-308</ref>
      <ref url="http://www.securityfocus.com/bid/7872" source="BID">7872</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:068" source="MANDRAKE">MDKSA-2003:068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3.3_1.1.0" />
        <vers prev="1" num="1.3.5" />
        <vers prev="1" num="1.3.5_1.2.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="8.2" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_advanced_server">
        <vers num="6.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="6.0" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0368" published="2004-02-03" name="CVE-2003-0368" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/924812" source="CERT-VN" patch="1" adv="1">VU#924812</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12221" source="XF" patch="1" adv="1">nokia-ggsn-ip-dos(12221)</ref>
      <ref url="http://www.securityfocus.com/bid/7854" source="BID" adv="1">7854</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a060903-1.txt" source="ATSTAKE">A060903-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="ggsn">
        <vers num="release_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0370" published="2003-06-16" name="CVE-2003-0370" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-192.html" source="REDHAT" patch="1" adv="1">RHSA-2003:192</ref>
      <ref url="http://www.kde.org/info/security/advisory-20030602-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20030602-1.txt</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-36.txt" source="TURBO">TLSA-2003-36</ref>
      <ref url="http://www.securityfocus.com/archive/1/320707" source="BUGTRAQ" adv="1">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-193.html" source="REDHAT">RHSA-2003:193</ref>
      <ref url="http://www.debian.org/security/2003/dsa-361" source="DEBIAN">DSA-361</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.html" source="FULLDISC">20030510 [forward]Apple Safari and Konqueror Embedded Common Name Verification Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/7520" source="BID">7520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="0.1" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers prev="1" num="2.2.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0371" published="2003-06-16" name="CVE-2003-0371" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370592729044&amp;w=2" source="BUGTRAQ">20030522 Prishtina FTP v.1.*: remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prishtina_soft" name="prishtina_ftp">
        <vers num="v.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0372" published="2003-06-16" name="CVE-2003-0372" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105369506714849&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030523 nessus NASL scripting engine security issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105364059803427&amp;w=2" source="BUGTRAQ" patch="1">20030522 Potential security vulnerability in Nessus</ref>
      <ref url="http://www.securityfocus.com/bid/7664" source="BID">7664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0373" published="2003-06-16" name="CVE-2003-0373" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105364059803427&amp;w=2" source="BUGTRAQ" patch="1">20030522 Potential security vulnerability in Nessus</ref>
      <ref url="http://www.securityfocus.com/bid/7664" source="BID">7664</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105369506714849&amp;w=2" source="BUGTRAQ">20030523 nessus NASL scripting engine security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0374" published="2003-06-16" name="CVE-2003-0374" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7664" source="BID">7664</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105364059803427&amp;w=2" source="BUGTRAQ">20030522 Potential security vulnerability in Nessus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0375" published="2003-06-16" name="CVE-2003-0375" modified="2008-10-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7662" source="BID">7662</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105363936402228&amp;w=2" source="BUGTRAQ" adv="1">20030522 XMB 1.8 Partagium cross site scripting vulnerability</ref>
      <ref url="http://forums.xmbforum.com/viewthread.php?tid=773046" source="MISC">http://forums.xmbforum.com/viewthread.php?tid=773046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.11" />
        <vers num="1.6" />
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0376" published="2003-06-16" name="CVE-2003-0376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large number of . (dot) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370625529452&amp;w=2" source="BUGTRAQ" adv="1">20030523 Eudora 5.2.1 buffer overflow DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0377" published="2003-06-16" name="CVE-2003-0377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370528728225&amp;w=2" source="BUGTRAQ" patch="1">20030523 iisPROTECT SQL injection in admin interface</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iisprotect" name="iisprotect">
        <vers num="2.2_r4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0378" published="2003-06-16" name="CVE-2003-0378" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/467828" source="CERT-VN" patch="1" adv="1">VU#467828</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=107579" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=107579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0379" published="2003-07-24" name="CVE-2003-0379" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00030.html" source="CONFIRM" patch="1" adv="1">http://lists.apple.com/mhonarc/security-announce/msg00030.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="afp_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0380" published="2003-07-02" name="CVE-2003-0380" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-314" source="DEBIAN" patch="1" adv="1">DSA-314</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0056.html" source="BUGTRAQ" patch="1" adv="1">20030606 atftpd bug</ref>
      <ref url="http://www.securityfocus.com/archive/82/323886/2003-06-02/2003-06-08/0" source="VULN-DEV" adv="1">20030604 possible remote buffer overflow in atftpd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atftpd" name="atftpd">
        <vers num="0.6.0" />
        <vers num="0.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0381" published="2003-07-24" name="CVE-2003-0381" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-323" source="DEBIAN" patch="1" adv="1">DSA-323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="norman_ramsey" name="noweb">
        <vers prev="1" num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0382" published="2003-07-02" name="CVE-2003-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-309" source="DEBIAN" patch="1" adv="1">DSA-309</ref>
      <ref url="http://www.securityfocus.com/bid/7708" source="BID">7708</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427580626001&amp;w=2" source="BUGTRAQ">20030509 BAZARR CODE NINER PINK TEAM GO GO GO</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.9.1" />
        <vers num="0.9.2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.3" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0385" published="2003-07-02" name="CVE-2003-0385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-310" source="DEBIAN" patch="1" adv="1">DSA-310</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105491469815197&amp;w=2" source="BUGTRAQ" adv="1">20030605 BAZARR LOCAL ROOT AGAIN. HI GUYS. DONT READ THIS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0.18" edition="" />
        <vers num="3.0.18" edition=":potato" />
        <vers num="3.0.23" edition="" />
        <vers num="3.0.23" edition=":woody" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0386" published="2003-07-02" name="CVE-2003-0386" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/978316" source="CERT-VN" patch="1" adv="1">VU#978316</ref>
      <ref url="http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0" source="BUGTRAQ" patch="1" adv="1">20030605 OpenSSH remote clent address restriction circumvention</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9894" source="OVAL">oval:org.mitre.oval:def:9894</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
      <ref url="http://www.securityfocus.com/bid/7831" source="BID">7831</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0698.html" source="REDHAT">RHSA-2006:0698</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0298.html" source="REDHAT">RHSA-2006:0298</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm</ref>
      <ref url="http://secunia.com/advisories/23680" source="SECUNIA">23680</ref>
      <ref url="http://secunia.com/advisories/22196" source="SECUNIA">22196</ref>
      <ref url="http://secunia.com/advisories/21724" source="SECUNIA">21724</ref>
      <ref url="http://secunia.com/advisories/21262" source="SECUNIA">21262</ref>
      <ref url="http://secunia.com/advisories/21129" source="SECUNIA">21129</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" source="SGI">20060703-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0388" published="2003-07-24" name="CVE-2003-0388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/06.16.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/06.16.03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105577915506761&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030616 FW: iDEFENSE Security Advisory 06.16.03: Linux-PAM getlogin() Spoofing</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-304.html" source="REDHAT">RHSA-2004:304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_morgan" name="linux_pam">
        <vers prev="1" num="0.77" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0389" published="2003-07-24" name="CVE-2003-0389" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0014.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0014.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0112.html" source="VULNWATCH" patch="1" adv="1">20030619 R7-0014: RSA SecurID ACE Agent Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="ace_agent">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0390" published="2003-07-02" name="CVE-2003-0390" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz" source="CONFIRM" patch="1">http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105371246204866&amp;w=2" source="BUGTRAQ">20030523 Re: Options Parsing Tool library buffer overflows.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105121918523320&amp;w=2" source="BUGTRAQ">20030424 SRT2003-04-24-1532 -  Options Parsing Tool library buffer overflows.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="james_theiler" name="opt">
        <vers prev="1" num="3.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0391" published="2003-07-02" name="CVE-2003-0391" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.magicwinmail.net/changelog.asp" source="MISC">http://www.magicwinmail.net/changelog.asp</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370528428222&amp;w=2" source="BUGTRAQ">20030523 Magic Winmail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="magic_winmail_server">
        <vers prev="1" num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0392" published="2003-07-02" name="CVE-2003-0392" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive letter argument (e.g. E:).</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105372353017778&amp;w=2" source="BUGTRAQ">20030523 ST FTP Service v3.0: directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="st" name="ftp_service">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0393" published="2003-07-02" name="CVE-2003-0393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services via FIN scans or Xmas scans.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7700" source="BID">7700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105380229532320&amp;w=2" source="BUGTRAQ">20030524 Some problems in Privatefirewall 3.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="privacyware" name="privatefirewall">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0394" published="2003-07-02" name="CVE-2003-0394" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105379530927567&amp;w=2" source="BUGTRAQ" patch="1">20030524 PHP source code injection in BLNews</ref>
      <ref url="http://www.securityfocus.com/bid/7677" source="BID">7677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blnews" name="blnews">
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0395" published="2003-07-02" name="CVE-2003-0395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105379741528925&amp;w=2" source="BUGTRAQ">20030524 UPB: Discussion Board/Web-Site Takeover</ref>
      <ref url="http://f0kp.iplus.ru/bz/024.en.txt" source="MISC">http://f0kp.iplus.ru/bz/024.en.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_outburst" name="ultimate_php_board_upb">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0396" published="2003-07-02" name="CVE-2003-0396" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=156242" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=156242</ref>
      <ref url="http://www.securityfocus.com/bid/7437" source="BID">7437</ref>
      <ref url="http://www.securiteam.com/exploits/5EP0M1P9PO.html" source="MISC">http://www.securiteam.com/exploits/5EP0M1P9PO.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154433926396&amp;w=2" source="BUGTRAQ">20030428 ATM  on Linux Exploit Code Release (les, local)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11903" source="XF">atmonlinux-les-command-bo(11903)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405560021979&amp;w=2" source="BUGTRAQ">20030524 ATM on linux Exploit(les,local)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux-atm" name="linux-atm">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0397" published="2003-07-02" name="CVE-2003-0397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7680" source="BID">7680</ref>
      <ref url="http://www.iss.net/security_center/static/12086.php" source="XF">fastrack-packet-0-bo(12086)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405708923565&amp;w=2" source="BUGTRAQ">20030526 The PACKET 0' DEATH FastTrack network vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sharman_networks" name="kazaa">
        <vers num="v2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0398" published="2003-07-02" name="CVE-2003-0398" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7685" source="BID" patch="1" adv="1">7685</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-016-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-016-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12077.php" source="XF" patch="1" adv="1">vignette-ssi-command-execution(12077)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405734223874&amp;w=2" source="BUGTRAQ">20030526 S21SEC-016 - Vignette SSI Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0399" published="2003-07-02" name="CVE-2003-0399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-017-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-017-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12076.php" source="XF" patch="1" adv="1">vignette-save-obtain-information(12076)</ref>
      <ref url="http://www.securityfocus.com/bid/7683" source="BID">7683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405874325673&amp;w=2" source="BUGTRAQ">20030526 S21SEC-017 - Vignette /vgn/legacy/save SQL access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0400" published="2003-06-30" name="CVE-2003-0400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/12075.php" source="XF" patch="1" adv="1">vignette-memory-leak(12075)</ref>
      <ref url="http://www.securityfocus.com/bid/7684" source="BID" adv="1">7684</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-018-en.txt" source="MISC" adv="1">http://www.s21sec.com/es/avisos/s21sec-018-en.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405985126857&amp;w=2" source="BUGTRAQ">20030526 S21SEC-018 - Vignette memory leak AIX Platform</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="6.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0401" published="2003-06-30" name="CVE-2003-0401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7688" source="BID" adv="1">7688</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-019-en.txt" source="MISC" adv="1">http://www.s21sec.com/es/avisos/s21sec-019-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12074.php" source="XF" adv="1">vignette-style-info-disclosure(12074)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405793324661&amp;w=2" source="BUGTRAQ">20030526 S21SEC-019 - Vignette /vgn/style internal information leak</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0402" published="2003-06-30" name="CVE-2003-0402" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s21sec.com/en/avisos/s21sec-020-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/en/avisos/s21sec-020-en.txt</ref>
      <ref url="http://www.securityfocus.com/bid/7691" source="BID" adv="1">7691</ref>
      <ref url="http://www.iss.net/security_center/static/12073.php" source="XF" adv="1">vignette-login-account-bruteforce(12073)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405880325755&amp;w=2" source="BUGTRAQ">20030526 S21SEC-020 - Vignette user enumeration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0403" published="2003-06-30" name="CVE-2003-0403" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-021-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-021-en.txt</ref>
      <ref url="http://www.securityfocus.com/bid/7694" source="BID" adv="1">7694</ref>
      <ref url="http://www.iss.net/security_center/static/12072.php" source="XF" adv="1">vignette-license-modification(12072)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405789924612&amp;w=2" source="BUGTRAQ">20030526 S21SEC-021 - Vignette License access and modification</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0404" published="2003-06-30" name="CVE-2003-0404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7687" source="BID" patch="1" adv="1">7687</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-023-en.txt" source="MISC" adv="1">http://www.s21sec.com/es/avisos/s21sec-023-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12071.php" source="XF" adv="1">vignette-multiple-xss(12071)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406028027360&amp;w=2" source="BUGTRAQ">20030526 S21SEC-023 -  Vignette multiple Cross Site Scripting vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0405" published="2003-06-30" name="CVE-2003-0405" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7692" source="BID" patch="1" adv="1">7692</ref>
      <ref url="http://www.securityfocus.com/bid/7690" source="BID" patch="1" adv="1">7690</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-024-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-024-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12070.php" source="XF" adv="1">vignette-tcl-code-execution(12070)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405922826197&amp;w=2" source="BUGTRAQ">20030526 S21SEC-024 - Vignette TCL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="5.0" />
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0406" published="2003-06-30" name="CVE-2003-0406" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7696" source="BID" adv="1">7696</ref>
      <ref url="http://www.iss.net/security_center/static/12083.php" source="XF" adv="1">palmvnc-plaintext-passwords(12083)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405691423389&amp;w=2" source="BUGTRAQ" adv="1">20030526 PalmVNC 1.40 Insecure Records</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palmvnc" name="palmvnc">
        <vers num="1.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0407" published="2003-06-30" name="CVE-2003-0407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7699" source="BID" adv="1">7699</ref>
      <ref url="http://www.iss.net/security_center/static/12087.php" source="XF" adv="1">batalla-naval-bo(12087)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405668423102&amp;w=2" source="BUGTRAQ" adv="1">20030526 [Priv8security_Advisory]_Batalla_Naval_remote_overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="batalla_naval">
        <vers num="1.0_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0408" published="2003-06-30" name="CVE-2003-0408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7703" source="BID" patch="1" adv="1">7703</ref>
      <ref url="http://www.iss.net/security_center/static/12131.php" source="XF" patch="1" adv="1">upclient-command-line-bo(12131)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405629622652&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030527 NuxAcid#002 - Buffer Overflow in UpClient</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_uptimes_project" name="upclient">
        <vers num="5.0b7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0409" published="2003-06-30" name="CVE-2003-0409" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7695" source="BID" adv="1">7695</ref>
      <ref url="http://www.iss.net/security_center/static/12107.php" source="XF" adv="1">webweaver-head-post-bo(12107)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405836025160&amp;w=2" source="BUGTRAQ" adv="1">20030527 BRS WebWeaver: POST and HEAD Overflaws</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brs" name="webweaver">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0410" published="2003-06-30" name="CVE-2003-0410" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7681" source="BID" patch="1" adv="1">7681</ref>
      <ref url="http://www.iss.net/security_center/static/12068.php" source="XF" patch="1" adv="1">analogx-proxy-url-bo(12068)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406759403978&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0082.html" source="VULNWATCH" patch="1" adv="1">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</ref>
      <ref url="http://www.analogx.com/contents/download/network/proxy.htm" source="CONFIRM" adv="1">http://www.analogx.com/contents/download/network/proxy.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="proxy">
        <vers num="4.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0411" published="2003-06-30" name="CVE-2003-0411" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7709" source="BID" patch="1" adv="1">7709</ref>
      <ref url="http://www.iss.net/security_center/static/12093.php" source="XF" patch="1" adv="1">sunone-jsp-source-disclosure(12093)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" patch="1" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" patch="1" adv="1">55221</ref>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0412" published="2003-06-30" name="CVE-2003-0412" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7711" source="BID" patch="1" adv="1">7711</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" patch="1" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" patch="1" adv="1">55221</ref>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0413" published="2003-06-30" name="CVE-2003-0413" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7710" source="BID" patch="1" adv="1">7710</ref>
      <ref url="http://www.iss.net/security_center/static/12095.php" source="XF" patch="1" adv="1">sunone-http-error-xss(12095)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" patch="1" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" patch="1" adv="1">55221</ref>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201009-1" source="SUNALERT">201009</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57605" source="SUNALERT">57605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0414" published="2003-06-30" name="CVE-2003-0414" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://www.securityfocus.com/bid/7712" source="BID" adv="1">7712</ref>
      <ref url="http://www.iss.net/security_center/static/12096.php" source="XF" adv="1">sunone-insecure-file-permissions(12096)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" adv="1">55221</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0415" published="2003-06-30" name="CVE-2003-0415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ytech.co.il/advisories/rpca/rpcaccess.htm" source="MISC" patch="1" adv="1">http://www.ytech.co.il/advisories/rpca/rpcaccess.htm</ref>
      <ref url="http://www.securityfocus.com/bid/7698" source="BID" patch="1" adv="1">7698</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105417988811698&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030528 Remote PC Access Server  2.2 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="access-remote-pc.com" name="remote_pc_access">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0416" published="2003-06-30" name="CVE-2003-0416" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7729" source="BID" adv="1">7729</ref>
      <ref url="http://www.iss.net/security_center/static/12108.php" source="XF" adv="1">bandmin-index-xss(12108)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418152212771&amp;w=2" source="BUGTRAQ" adv="1">20030528 Bandmin 1.4 XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bandmin" name="bandmin">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0417" published="2003-06-30" name="CVE-2003-0417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7717" source="BID" adv="1">7717</ref>
      <ref url="http://www.iss.net/security_center/static/12103.php" source="XF" adv="1">sonhserver-pipe-directory-traversal(12103)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105417983711685&amp;w=2" source="BUGTRAQ" adv="1">20030529 Son hServer v0.2: directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="super-m" name="son_hserver">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0418" published="2003-07-24" name="CVE-2003-0418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/471084" source="CERT-VN" patch="1" adv="1">VU#471084</ref>
      <ref url="http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt" source="MISC" patch="1" adv="1">http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105519179005065&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030609 Linux 2.0 remote info leak from too big icmp citation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.29" />
        <vers num="2.0.3" />
        <vers num="2.0.30" />
        <vers num="2.0.31" />
        <vers num="2.0.32" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0419" published="2003-07-24" name="CVE-2003-0419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/06.11.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/06.11.03.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smc_networks" name="barricade_wireless_cable_dsl_broadband_router">
        <vers num="smc7004vwbr" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0420" published="2003-06-13" name="CVE-2003-0420" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JPLA-5NTL8E" source="MISC" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JPLA-5NTL8E</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12342" source="XF" patch="1" adv="1">macos-dsimportexport-obtain-information(12342)</ref>
      <ref url="http://www.securityfocus.com/bid/7894" source="BID" patch="1" adv="1">7894</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3165" source="AUSCERT" patch="1" adv="1">ESB-2003.0415</ref>
      <ref url="http://secunia.com/advisories/9025/" source="SECUNIA" patch="1" adv="1">9025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0421" published="2003-08-27" name="CVE-2003-0421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0422" published="2003-08-27" name="CVE-2003-0422" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0423" published="2003-08-27" name="CVE-2003-0423" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0424" published="2003-08-27" name="CVE-2003-0424" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0425" published="2003-08-27" name="CVE-2003-0425" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0426" published="2003-08-27" name="CVE-2003-0426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0427" published="2003-07-24" name="CVE-2003-0427" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-320" source="DEBIAN" patch="1" adv="1">DSA-320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10194" source="OVAL">oval:org.mitre.oval:def:10194</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-506.html" source="REDHAT">RHSA-2005:506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:647" source="OVAL" sig="1">oval:org.mitre.oval:def:647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miod_vallat" name="mikmod">
        <vers num="3.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0428" published="2003-07-24" name="CVE-2003-0428" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/542540" source="CERT-VN">VU#542540</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:75" source="OVAL" sig="1">oval:org.mitre.oval:def:75</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0429" published="2003-07-24" name="CVE-2003-0429" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:84" source="OVAL" sig="1">oval:org.mitre.oval:def:84</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0430" published="2003-07-24" name="CVE-2003-0430" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:88" source="OVAL" sig="1">oval:org.mitre.oval:def:88</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0431" published="2003-07-24" name="CVE-2003-0431" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:101" source="OVAL" sig="1">oval:org.mitre.oval:def:101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0432" published="2003-07-24" name="CVE-2003-0432" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:106" source="OVAL" sig="1">oval:org.mitre.oval:def:106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0433" published="2003-07-24" name="CVE-2003-0433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in gnocatan 0.6.1 and earlier allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-315" source="DEBIAN" patch="1" adv="1">DSA-315</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnocatan-develop" name="gnocatan">
        <vers prev="1" num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0434" published="2003-07-24" name="CVE-2003-0434" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/200132" source="CERT-VN">VU#200132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-197.html" source="REDHAT" patch="1" adv="1">RHSA-2003:197</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-196.html" source="REDHAT" patch="1" adv="1">RHSA-2003:196</ref>
      <ref url="http://secunia.com/advisories/9038" source="SECUNIA">9038</ref>
      <ref url="http://secunia.com/advisories/9037" source="SECUNIA">9037</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105777963019186&amp;w=2" source="BUGTRAQ">20030709 xpdf vulnerability - CAN-2003-0434</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.html" source="FULLDISC">20030613 -10Day CERT Advisory on PDF Files</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:071" source="MANDRAKE">MDKSA-2003:071</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:664" source="OVAL" sig="1">oval:org.mitre.oval:def:664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="5.0.6" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="1.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0435" published="2003-07-24" name="CVE-2003-0435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-322" source="DEBIAN" patch="1" adv="1">DSA-322</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105553002105111&amp;w=2" source="BUGTRAQ" adv="1">20030612 BAZARR THUG LIFE , DONT READ OR VIRUS INFECT YOU</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typespeed" name="typespeed">
        <vers prev="1" num="0.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0436" published="2003-07-24" name="CVE-2003-0436" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7865" source="BID" patch="1" adv="1">7865</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html" source="FULLDISC">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0437" published="2003-07-24" name="CVE-2003-0437" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7866" source="BID" patch="1" adv="1">7866</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html" source="FULLDISC">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0438" published="2003-07-24" name="CVE-2003-0438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-325" source="DEBIAN" patch="1" adv="1">DSA-325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yuuichi_teranishi" name="eldav">
        <vers prev="1" num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0440" published="2003-08-18" name="CVE-2003-0440" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-234.html" source="REDHAT" patch="1" adv="1">RHSA-2003:234</ref>
      <ref url="http://www.debian.org/security/2003/dsa-339" source="DEBIAN" patch="1" adv="1">DSA-339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-231.html" source="REDHAT">RHSA-2003:231</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:569" source="OVAL" sig="1">oval:org.mitre.oval:def:569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="semi" name="semi">
        <vers num="1.14.3" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0441" published="2004-03-03" name="CVE-2003-0441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7988" source="BID" patch="1" adv="1">7988</ref>
      <ref url="http://www.debian.org/security/2003/dsa-326" source="DEBIAN" patch="1" adv="1">DSA-326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12381" source="XF" adv="1">orvillewrite-variables-bo(12381)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orville-write" name="orville-write">
        <vers num="2.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0442" published="2003-07-24" name="CVE-2003-0442" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-204.html" source="REDHAT" patch="1" adv="1">RHSA-2003:204</ref>
      <ref url="http://shh.thathost.com/secadv/2003-05-11-php.txt" source="MISC" patch="1" adv="1">http://shh.thathost.com/secadv/2003-05-11-php.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105760591228031&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)</ref>
      <ref url="http://www.securityfocus.com/bid/7761" source="BID">7761</ref>
      <ref url="http://www.debian.org/security/2003/dsa-351" source="DEBIAN">DSA-351</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105449314612963&amp;w=2" source="BUGTRAQ" adv="1">20030530 PHP Trans SID  XSS (Was: New php release with security fixes)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12259" source="XF">php-session-id-xss(12259)</ref>
      <ref url="http://www.turbolinux.co.jp/security/2003/TLSA-2003-47j.txt" source="TURBO">TLSA-2003-47</ref>
      <ref url="http://www.securitytracker.com/id?1008653" source="SECTRACK">1008653</ref>
      <ref url="http://www.osvdb.org/4758" source="OSVDB">4758</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:082" source="MANDRAKE">MDKSA-2003:082</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-112.shtml" source="CIAC">N-112</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" source="CONECTIVA">CLSA-2003:691</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:485" source="OVAL" sig="1">oval:org.mitre.oval:def:485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.3.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0444" published="2004-03-29" name="CVE-2003-0444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12462" source="XF" patch="1" adv="1">gtksee-png-bo(12462)</ref>
      <ref url="http://www.securityfocus.com/bid/8061" source="BID" patch="1" adv="1">8061</ref>
      <ref url="http://www.debian.org/security/2003/dsa-337" source="DEBIAN" patch="1" adv="1">DSA-337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtksee" name="gtksee">
        <vers num="0.5" />
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0445" published="2003-07-24" name="CVE-2003-0445" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-328" source="DEBIAN" patch="1" adv="1">DSA-328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfs" name="webfs">
        <vers prev="1" num="1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0446" published="2003-07-24" name="CVE-2003-0446" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.greymagic.com/adv/gm013-ie/" source="MISC" adv="1">http://security.greymagic.com/adv/gm013-ie/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105585001905002&amp;w=2" source="NTBUGTRAQ" adv="1">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105595990924165&amp;w=2" source="BUGTRAQ" adv="1">20030617 Re: [Full-Disclosure] Cross-Site Scripting in Unparsable XML Files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105585986015421&amp;w=2" source="BUGTRAQ" adv="1">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005762.html" source="FULLDISC">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12334" source="XF">ie-msxml-xss(12334)</ref>
      <ref url="http://www.securityfocus.com/bid/7938" source="BID">7938</ref>
      <ref url="http://www.osvdb.org/3065" source="OSVDB">3065</ref>
      <ref url="http://secunia.com/advisories/9055" source="SECUNIA">9055</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0120.html" source="BUGTRAQ">20030617 Re: Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0447" published="2003-07-24" name="CVE-2003-0447" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://security.greymagic.com/adv/gm014-ie/" source="MISC" adv="1">http://security.greymagic.com/adv/gm014-ie/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105585142406147&amp;w=2" source="NTBUGTRAQ" adv="1">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105585933614773&amp;w=2" source="BUGTRAQ" adv="1">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html" source="FULLDISC">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0448" published="2003-07-24" name="CVE-2003-0448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105588111714856&amp;w=2" source="BUGTRAQ" adv="1">20030618 Portmon file arbitrary read/write access vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aboleo.net" name="portmon">
        <vers prev="1" num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0449" published="2003-08-07" name="CVE-2003-0449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt" source="MISC" patch="1" adv="1">http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt</ref>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt" source="MISC" patch="1" adv="1">http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105561189625082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030614 SRT2003-06-13-1009 - Progress _dbagent -installdir dlopen() issue</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105561134624665&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030614 SRT2003-06-13-0945 - Progress PATH based dlopen() issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="progress" name="database">
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0450" published="2003-08-07" name="CVE-2003-0450" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-40.txt" source="TURBO" patch="1" adv="1">TLSA-2003-40</ref>
      <ref url="http://www.debian.org/security/2003/dsa-321" source="DEBIAN" patch="1" adv="1">DSA-321</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063" source="MISC" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_030_radiusd_cistron.html" source="SUSE">SuSE-SA:2003:030</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000664" source="CONECTIVA">CLA-2003:664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cistron" name="radius_daemon">
        <vers prev="1" num="1.6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0451" published="2003-08-07" name="CVE-2003-0451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-327" source="DEBIAN" patch="1" adv="1">DSA-327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xblockout" name="xbl">
        <vers prev="1" num="1.0j" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0452" published="2003-08-07" name="CVE-2003-0452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-329" source="DEBIAN" patch="1" adv="1">DSA-329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gunnar_ritter" name="osh">
        <vers prev="1" num="1.7-10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0453" published="2003-08-07" name="CVE-2003-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-348" source="DEBIAN">DSA-348</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105613905425563&amp;w=2" source="BUGTRAQ" adv="1">20030620 BAZARR FAREWELL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ehud_gavron" name="traceroute-nanog">
        <vers num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0454" published="2003-08-07" name="CVE-2003-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-334" source="DEBIAN">DSA-334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_rumsey" name="xgalaga">
        <vers num="2.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0455" published="2003-08-07" name="CVE-2003-0455" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-331" source="DEBIAN" patch="1" adv="1">DSA-331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-494.html" source="REDHAT">RHSA-2004:494</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105786393628728&amp;w=2" source="BUGTRAQ">20030710 [OpenPKG-SA-2003.034] OpenPKG Security Advisory (imagemagick)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="libmagick_library">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0456" published="2003-08-18" name="CVE-2003-0456" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8075" source="BID" patch="1" adv="1">8075</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105733894003737&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030701 VisNetic WebSite Path Disclosure Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0002.html" source="VULNWATCH" patch="1" adv="1">20030701 VisNetic WebSite Path Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12483" source="XF">visnetic-website-path-disclosure(12483)</ref>
      <ref url="http://www.krusesecurity.dk/advisories/vis0103.txt" source="MISC">http://www.krusesecurity.dk/advisories/vis0103.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="visnetic_website">
        <vers num="3.5.13" />
        <vers num="3.5.15" />
        <vers num="3.5.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0458" published="2003-08-18" name="CVE-2003-0458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8080" source="BID" patch="1" adv="1">8080</ref>
      <ref url="http://www.securityfocus.com/advisories/5545" source="HP" adv="1">SSRT3488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="nonstop_seeview_server_gateway">
        <vers num="d40.00" />
        <vers num="d41.00" />
        <vers num="d42.00" />
        <vers num="d42.01" />
        <vers num="d43.00" />
        <vers num="d43.01" />
        <vers num="d43.02" />
        <vers num="d44.00" />
        <vers num="d44.01" />
        <vers num="d44.02" />
        <vers num="d45.00" />
        <vers num="d45.01" />
        <vers num="d46.00" />
        <vers num="d47.00" />
        <vers num="d48.00" />
        <vers num="d48.01" />
        <vers num="d48.02" />
        <vers num="d48.03" />
        <vers num="g01.00" />
        <vers num="g02.00" />
        <vers num="g03.00" />
        <vers num="g04.00" />
        <vers num="g05.00" />
        <vers num="g05.01" />
        <vers num="g06.00" />
        <vers num="g06.01" />
        <vers num="g06.03" />
        <vers num="g06.04" />
        <vers num="g06.05" />
        <vers num="g06.06" />
        <vers num="g06.07" />
        <vers num="g06.08" />
        <vers num="g06.09" />
        <vers num="g06.10" />
        <vers num="g06.11" />
        <vers num="g06.12" />
        <vers num="g06.13" />
        <vers num="g06.14" />
        <vers num="g06.15" />
        <vers num="g06.16" />
        <vers num="g06.17" />
        <vers num="g06.18" />
        <vers num="g06.19" />
        <vers num="g06.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0459" published="2003-08-27" name="CVE-2003-0459" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-236.html" source="REDHAT" patch="1" adv="1">RHSA-2003:236</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-235.html" source="REDHAT" patch="1" adv="1">RHSA-2003:235</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105986238428061&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030802 [slackware-security]  KDE packages updated (SSA:2003-213-01)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-45.txt" source="TURBO">TLSA-2003-45</ref>
      <ref url="http://www.kde.org/info/security/advisory-20030729-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20030729-1.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-361" source="DEBIAN">DSA-361</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007300.html" source="FULLDISC">20030729 KDE Security Advisory: Konqueror Referrer Authentication Leak</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:079" source="MANDRAKE">MDKSA-2003:079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" source="CONECTIVA">CLA-2003:747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:411" source="OVAL" sig="1">oval:org.mitre.oval:def:411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="0.1" />
      </prod>
      <prod vendor="redhat" name="analog_real-time_synthesizer">
        <vers num="2.1.1-5" edition="" />
        <vers num="2.1.1-5" edition=":i386" />
        <vers num="2.2-11" edition="" />
        <vers num="2.2-11" edition=":ia64" />
        <vers num="2.2-11" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="3.0.3-13" edition="" />
        <vers num="3.0.3-13" edition=":i386_dev" />
        <vers num="3.0.3-13" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="kdelibs">
        <vers num="2.1.1-5" edition="" />
        <vers num="2.1.1-5" edition=":i386" />
        <vers num="2.2-11" edition="" />
        <vers num="2.2-11" edition=":ia64" />
        <vers num="2.2-11" edition=":i386" />
        <vers num="3.0.0-10" edition="" />
        <vers num="3.0.0-10" edition=":i386" />
        <vers num="3.1-10" edition="" />
        <vers num="3.1-10" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="kdelibs_devel">
        <vers num="2.1.1-5" edition="" />
        <vers num="2.1.1-5" edition=":i386_dev" />
        <vers num="2.2-11" edition="" />
        <vers num="2.2-11" edition=":ia64_dev" />
        <vers num="2.2-11" edition=":i386_dev" />
        <vers num="3.0.0-10" edition="" />
        <vers num="3.0.0-10" edition=":i386_dev" />
        <vers num="3.0.3-8" edition="" />
        <vers num="3.0.3-8" edition=":i386_dev" />
        <vers num="3.1-10" edition="" />
        <vers num="3.1-10" edition=":i386_dev" />
      </prod>
      <prod vendor="redhat" name="kdelibs_sound">
        <vers num="2.1.1-5" edition="" />
        <vers num="2.1.1-5" edition=":i386_sound" />
        <vers num="2.2-11" edition="" />
        <vers num="2.2-11" edition=":i386_sound" />
        <vers num="2.2-11" edition=":ia64_sound" />
      </prod>
      <prod vendor="redhat" name="kdelibs_sound_devel">
        <vers num="2.1.1-5" edition="" />
        <vers num="2.1.1-5" edition=":i386_sound_dev" />
        <vers num="2.2-11" edition="" />
        <vers num="2.2-11" edition=":ia64_sound_dev" />
        <vers num="2.2-11" edition=":i386_sound_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0460" published="2003-08-27" name="CVE-2003-0460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/694428" source="CERT-VN">VU#694428</ref>
      <ref url="http://www.apache.org/dist/httpd/Announcement.html" source="CONFIRM" patch="1">http://www.apache.org/dist/httpd/Announcement.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="1.3.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0461" published="2003-08-27" name="CVE-2003-0461" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT">RHSA-2004:188</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html" source="MISC">http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9330" source="OVAL">oval:org.mitre.oval:def:9330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:997" source="OVAL" sig="1">oval:org.mitre.oval:def:997</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:304" source="OVAL" sig="1">oval:org.mitre.oval:def:304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0462" published="2003-08-27" name="CVE-2003-0462" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:309" source="OVAL" sig="1">oval:org.mitre.oval:def:309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":ppc" />
        <vers num="9.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0463" reject="1" published="2003-12-31" name="CVE-2003-0463" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0464" published="2003-08-27" name="CVE-2003-0464" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:311" source="OVAL" sig="1">oval:org.mitre.oval:def:311</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0465" published="2003-08-18" name="CVE-2003-0465" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as opposed to the expected behavior of strncpy as implemented in libc, which could lead to information leaks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT" patch="1" adv="1">RHSA-2004:188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10285" source="OVAL">oval:org.mitre.oval:def:10285</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796415223490&amp;w=2" source="CONFIRM" adv="1">http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796415223490&amp;w=2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796021120436&amp;w=2" source="CONFIRM" adv="1">http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796021120436&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0466" published="2003-08-27" name="CVE-2003-0466" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/743092" source="CERT-VN" adv="1">VU#743092</ref>
      <ref url="http://www.securityfocus.com/bid/8315" source="BID" patch="1" adv="1">8315</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12785" source="XF">libc-realpath-offbyone-bo(12785)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-46.txt" source="TURBO">TLSA-2003-46</ref>
      <ref url="http://www.securityfocus.com/archive/1/425061/100/0/threaded" source="BUGTRAQ">20060214 Re: Latest wu-ftpd exploit :-s</ref>
      <ref url="http://www.securityfocus.com/archive/1/424852/100/0/threaded" source="BUGTRAQ">20060213 Latest wu-ftpd exploit :-s</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-246.html" source="REDHAT">RHSA-2003:246</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-245.html" source="REDHAT">RHSA-2003:245</ref>
      <ref url="http://www.osvdb.org/6602" source="OSVDB">6602</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_032_wuftpd.html" source="SUSE">SuSE-SA:2003:032</ref>
      <ref url="http://www.debian.org/security/2003/dsa-357" source="DEBIAN">DSA-357</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001257.1-1" source="SUNALERT">1001257</ref>
      <ref url="http://securitytracker.com/id?1007380" source="SECTRACK">1007380</ref>
      <ref url="http://secunia.com/advisories/9535" source="SECUNIA">9535</ref>
      <ref url="http://secunia.com/advisories/9447" source="SECUNIA">9447</ref>
      <ref url="http://secunia.com/advisories/9446" source="SECUNIA">9446</ref>
      <ref url="http://secunia.com/advisories/9423" source="SECUNIA">9423</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106002488209129&amp;w=2" source="BUGTRAQ">20030804 Off-by-one Buffer Overflow Vulnerability in BSD libc realpath(3)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001702232325&amp;w=2" source="BUGTRAQ">20030804 wu-ftpd-2.6.2 off-by-one remote exploit.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001410028809&amp;w=2" source="FREEBSD">FreeBSD-SA-03:08</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105967301604815&amp;w=2" source="BUGTRAQ" adv="1">20030731 wu-ftpd fb_realpath() off-by-one bug</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-019-01" source="IMMUNIX">IMNX-2003-7+-019-01</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0065.html" source="VULNWATCH" adv="1">20030731 wu-ftpd fb_realpath() off-by-one bug</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-011.txt.asc" source="NETBSD">NetBSD-SA2003-011.txt.asc</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:080" source="MANDRAKE">MDKSA-2003:080</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1970" source="OVAL" sig="1">oval:org.mitre.oval:def:1970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="wu_ftpd">
        <vers num="2.6.1-16" edition="" />
        <vers num="2.6.1-16" edition=":powerpc" />
        <vers num="2.6.1-16" edition=":i386" />
        <vers num="2.6.1-18" edition="" />
        <vers num="2.6.1-18" edition=":ia64" />
        <vers num="2.6.1-18" edition=":i386" />
        <vers num="2.6.2-5" edition="" />
        <vers num="2.6.2-5" edition=":i386" />
        <vers num="2.6.2-8" edition="" />
        <vers num="2.6.2-8" edition=":i386" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.6" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="5.0" edition="alpha" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" />
        <vers num="1.6.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0467" published="2003-08-27" name="CVE-2003-0467" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105985703724758&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030802 [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0468" published="2003-08-27" name="CVE-2003-0468" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-363" source="DEBIAN" patch="1" adv="1">DSA-363</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001525130257&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref url="http://www.securityfocus.com/bid/8333" source="BID">8333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-251.html" source="REDHAT">RHSA-2003:251</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_033_postfix.html" source="SUSE">SuSE-SA:2003:033</ref>
      <ref url="http://secunia.com/advisories/9433" source="SECUNIA">9433</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081" source="MANDRAKE">MDKSA-2003:081</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717" source="CONECTIVA">CLA-2003:717</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:522" source="OVAL" sig="1">oval:org.mitre.oval:def:522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wietse_venema" name="postfix">
        <vers num="1.0.21" />
        <vers num="1.1.11" />
        <vers num="1999-09-06" />
        <vers num="1999-12-31" />
        <vers num="2000-02-28" />
        <vers num="2001-11-15" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0469" published="2003-08-07" name="CVE-2003-0469" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/823260" source="CERT-VN">VU#823260</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-14.html" source="CERT">CA-2003-14</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-023.asp" source="MS" patch="1" adv="1">MS03-023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105639925122961&amp;w=2" source="BUGTRAQ">20030622 Internet Explorer >=5.0 : Buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006067.html" source="FULLDISC">20030625 Re: Internet Explorer >=5.0 : Buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006155.html" source="FULLDISC">20030701 PoC for Internet Explorer >=5.0 buffer overflow (trivial exploit for hard case).</ref>
      <ref url="http://www.securityfocus.com/bid/8016" source="BID">8016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0470" published="2003-08-07" name="CVE-2003-0470" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/527228" source="CERT-VN">VU#527228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105647537823877&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030624 [Symantec Security Advisor] Symantec Security Check ActiveX Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12423" source="XF">symantec-security-activex-bo(12423)</ref>
      <ref url="http://www.securityfocus.com/bid/8008" source="BID">8008</ref>
      <ref url="http://securitytracker.com/id?1007029" source="SECTRACK">1007029</ref>
      <ref url="http://secunia.com/advisories/9091" source="SECUNIA">9091</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html" source="FULLDISC">20030622 Symantec ActiveX control buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="security_check">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0471" published="2003-08-07" name="CVE-2003-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105647081418155&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030624 Remote Buffer Overrun WebAdmin.exe</ref>
      <ref url="http://www.securityfocus.com/bid/8024" source="BID">8024</ref>
      <ref url="http://www.osvdb.org/2207" source="OSVDB">2207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105648385900792&amp;w=2" source="BUGTRAQ">20030624 Re: WebAdmin from ALT-N remote exploit PoC</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0472" published="2003-08-07" name="CVE-2003-0472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IPv6 capability in IRIX 6.5.19 allows remote attackers to cause a denial of service (hang) in inetd via port scanning.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" source="SGI" patch="1" adv="1">20030607-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12676" source="XF">irix-inetd-portscan-dos(12676)</ref>
      <ref url="http://www.securityfocus.com/bid/8027" source="BID">8027</ref>
      <ref url="http://www.osvdb.org/8585" source="OSVDB">8585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0473" published="2003-08-07" name="CVE-2003-0473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" source="SGI" patch="1" adv="1">20030607-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12677" source="XF">irix-snoop-gain-privileges(12677)</ref>
      <ref url="http://www.securityfocus.com/bid/8029" source="BID">8029</ref>
      <ref url="http://www.osvdb.org/8586" source="OSVDB">8586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0474" published="2003-08-07" name="CVE-2003-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673543626636&amp;w=2" source="BUGTRAQ" adv="1">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105049794801319&amp;w=2" source="BUGTRAQ" adv="1">20030416 SFAD03-001: iWeb Mini Web Server Remote Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashley_brown" name="iweb_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0475" published="2003-08-07" name="CVE-2003-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673543626636&amp;w=2" source="BUGTRAQ" adv="1">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105640001823769&amp;w=2" source="BUGTRAQ" adv="1">20030623 TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashley_brown" name="iweb_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0476" published="2003-08-07" name="CVE-2003-0476" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-368.html" source="REDHAT" patch="1" adv="1">RHSA-2003:368</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-408.html" source="REDHAT">RHSA-2003:408</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105664924024009&amp;w=2" source="BUGTRAQ">20030626 Linux 2.4.x execve() file read race vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:327" source="OVAL" sig="1">oval:org.mitre.oval:def:327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0477" published="2003-08-07" name="CVE-2003-0477" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wzdftpd.net/changea.html" source="CONFIRM" patch="1" adv="1">http://www.wzdftpd.net/changea.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105674242105302&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030627 wzdftpd remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wzdftpd" name="wzdftpd">
        <vers prev="1" num="0.1_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0478" published="2003-08-07" name="CVE-2003-0478" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673555726823&amp;w=2" source="BUGTRAQ">20030627 Bahamut DoS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673489525906&amp;w=2" source="BUGTRAQ">20030627 Re: Bahamut IRCd &lt;= 1.4.35 and several derived daemons</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105665996104723&amp;w=2" source="BUGTRAQ">20030626 Bahamut IRCd &lt;= 1.4.35 and several derived daemons</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andromede" name="adromedeircd">
        <vers num="1.2.3" />
      </prod>
      <prod vendor="daniel_moss" name="methane">
        <vers num="0.1.1" />
      </prod>
      <prod vendor="hans_westerhof" name="digatech">
        <vers num="1.2.1" />
      </prod>
      <prod vendor="wenet" name="ircd-ru">
        <vers num="" />
      </prod>
      <prod vendor="bahamut" name="ircd">
        <vers prev="1" num="1.4.35" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0479" published="2003-08-07" name="CVE-2003-0479" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673452325230&amp;w=2" source="BUGTRAQ" adv="1">20030627 WebBBS Guestbook : Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="affordable_web_space_design" name="affordable_web_space_design_webbbs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0480" published="2003-08-07" name="CVE-2003-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673688529147&amp;w=2" source="BUGTRAQ">20030627 VMware Workstation 4.0: Possible privilege escalation on the host</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0481" published="2003-08-07" name="CVE-2003-0481" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638743109781&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030623 [KSA-001] Multiple vulnerabilities in Tutos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gero_kohnert" name="tutos">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0482" published="2003-08-07" name="CVE-2003-0482" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638743109781&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030623 [KSA-001] Multiple vulnerabilities in Tutos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gero_kohnert" name="tutos">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0483" published="2003-08-07" name="CVE-2003-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638720409307&amp;w=2" source="BUGTRAQ">20030623 Many XSS Vulnerabilities in XMB Forum.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0484" published="2003-08-07" name="CVE-2003-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105639883722514&amp;w=2" source="BUGTRAQ">20030621 XSS Exploit In phpBB viewtopic.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0485" published="2003-08-07" name="CVE-2003-0485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7997" source="BID" adv="1">7997</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105613243117155&amp;w=2" source="BUGTRAQ" adv="1">20030620 SRT2003-06-20-1232 - Progress 4GL Compiler datatype overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="progress" name="4gl_compiler">
        <vers num="9.1" edition="d06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0486" published="2003-08-07" name="CVE-2003-0486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12366" source="XF" patch="1" adv="1">phpbb-viewtopic-sql-injection(12366)</ref>
      <ref url="http://www.securityfocus.com/bid/7979" source="BID" patch="1" adv="1">7979</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?t=112052" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=112052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105607263130644&amp;w=2" source="BUGTRAQ">20030619 phpBB password disclosure by sql injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0487" published="2003-08-07" name="CVE-2003-0487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7967" source="BID" patch="1" adv="1">7967</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12368" source="XF" adv="1">kerio-multiple-modules-bo(12368)</ref>
      <ref url="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" source="MISC" adv="1">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105596982503760&amp;w=2" source="BUGTRAQ" adv="1">20030618 Multiple buffer overflows and XSS in Kerio MailServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0488" published="2003-08-07" name="CVE-2003-0488" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7968" source="BID" patch="1" adv="1">7968</ref>
      <ref url="http://www.securityfocus.com/bid/7966" source="BID" patch="1" adv="1">7966</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12367" source="XF" adv="1">kerio-multiple-modules-xss(12367)</ref>
      <ref url="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" source="MISC" adv="1">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105596982503760&amp;w=2" source="BUGTRAQ" adv="1">20030618 Multiple buffer overflows and XSS in Kerio MailServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0489" published="2003-08-07" name="CVE-2003-0489" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-330" source="DEBIAN" patch="1" adv="1">DSA-330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_c._toren" name="tcptraceroute">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0490" published="2003-08-07" name="CVE-2003-0490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105579526026992&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030616 Dantz Retrospect Client 5.0.540 for Mac OS X - permission issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dantz" name="retrospect_client">
        <vers num="5.0.540" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0491" published="2003-08-07" name="CVE-2003-0491" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=105577873506147&amp;w=2" source="BUGTRAQ">20030616 Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials"</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=105577873506147&amp;w=2" source="VULN-DEV">20030614 Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mytutorials" name="tutorials">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0492" published="2003-08-07" name="CVE-2003-0492" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12325" source="XF" adv="1">snitz-search-xss(12325)</ref>
      <ref url="http://www.securityfocus.com/bid/7922" source="BID" adv="1">7922</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578322012128&amp;w=2" source="BUGTRAQ">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0493" published="2003-08-07" name="CVE-2003-0493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7924" source="BID" adv="1">7924</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578322012128&amp;w=2" source="BUGTRAQ" adv="1">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0494" published="2003-08-07" name="CVE-2003-0494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12326" source="XF" adv="1">snitz-forums-password-reset(12326)</ref>
      <ref url="http://www.securityfocus.com/bid/7925" source="BID" adv="1">7925</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578322012128&amp;w=2" source="BUGTRAQ" adv="1">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0495" published="2003-08-07" name="CVE-2003-0495" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12304" source="XF" adv="1">lednews-message-xss(12304)</ref>
      <ref url="http://www.securityfocus.com/bid/7920" source="BID">7920</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578330812212&amp;w=2" source="BUGTRAQ" adv="1">20030615 XSS Vulnerability in LedNews (CGI/Perl) v0.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledscripts.com" name="lednews">
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0496" published="2003-08-18" name="CVE-2003-0496" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a070803-1.txt" source="ATSTAKE" patch="1" adv="1">A070803-1</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html" source="VULNWATCH" patch="1" adv="1">20030709 Pipe Filename Local Privilege Escalation FAQ</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830986720243&amp;w=2" source="BUGTRAQ">20030715 CreateFile exploit, (working)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820282607865&amp;w=2" source="BUGTRAQ">20030714 @stake named pipe exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0497" published="2003-08-07" name="CVE-2003-0497" modified="2012-02-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cach�Ã�© Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0498" published="2003-08-07" name="CVE-2003-0498" modified="2012-02-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cach�Ã�© Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0499" published="2003-08-07" name="CVE-2003-0499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105700201923438&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.17.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0500" published="2003-08-07" name="CVE-2003-0500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-338" source="DEBIAN" patch="1" adv="1">DSA-338</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html" source="FULLDISC">20030618 SQL Inject in ProFTPD login against Postgresql using mod_sql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.9_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0501" published="2003-08-07" name="CVE-2003-0501" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT" patch="1" adv="1">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105621758104242" source="BUGTRAQ" adv="1">20030620 Linux /proc sensitive information disclosure</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:328" source="OVAL" sig="1">oval:org.mitre.oval:def:328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0502" published="2003-08-27" name="CVE-2003-0502" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers prev="1" num="4.1.3g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0503" published="2003-08-07" name="CVE-2003-0503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105724538222772&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105725489003575&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</ref>
      <ref url="http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html" source="MISC">http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0504" published="2003-08-07" name="CVE-2003-0504" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718361607981&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 [KSA-003] Cross Site Scripting Vulnerability in Phpgroupware</ref>
      <ref url="http://www.security-corporation.com/articles-20030702-005.html" source="MISC">http://www.security-corporation.com/articles-20030702-005.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-365" source="DEBIAN">DSA-365</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:077" source="MANDRAKE">MDKSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000697" source="CONECTIVA">CLA-2003:697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.14.003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0505" published="2003-08-07" name="CVE-2003-0505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7931" source="BID" patch="1" adv="1">7931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105716650021546&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0506" published="2003-08-07" name="CVE-2003-0506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105716650021546&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0507" published="2003-08-07" name="CVE-2003-0507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/594108" source="CERT-VN">VU#594108</ref>
      <ref url="http://support.microsoft.com/default.aspx?kbid=319709" source="MSKB" patch="1" adv="1">Q319709</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105716669921775&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 CORE-2003-0305-03: Active Directory Stack Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/7930" source="BID">7930</ref>
      <ref url="http://secunia.com/advisories/9171" source="SECUNIA">9171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0508" published="2003-08-07" name="CVE-2003-0508" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105709569312583&amp;w=2" source="BUGTRAQ" adv="1">20030701 [sec-labs] Adobe Acrobat Reader &lt;=5.0.7 Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105785749721291&amp;w=2" source="BUGTRAQ">20030709 Acroread 5.0.7 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0509" published="2003-08-07" name="CVE-2003-0509" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105709450711395&amp;w=2" source="BUGTRAQ" adv="1">20030701 CyberStrong Shopping Cart - Advisory &amp; Exploit Code</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12485" source="XF">cyberstrongeshop-multiple-sql-injection(12485)</ref>
      <ref url="http://www.securityfocus.com/bid/14112" source="BID">14112</ref>
      <ref url="http://www.securityfocus.com/bid/14103" source="BID">14103</ref>
      <ref url="http://www.securityfocus.com/bid/14101" source="BID">14101</ref>
      <ref url="http://www.osvdb.org/10100" source="OSVDB">10100</ref>
      <ref url="http://www.osvdb.org/10099" source="OSVDB">10099</ref>
      <ref url="http://www.osvdb.org/10098" source="OSVDB">10098</ref>
      <ref url="http://securitytracker.com/id?1007092" source="SECTRACK">1007092</ref>
      <ref url="http://secunia.com/advisories/9165" source="SECUNIA">9165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyberstrong" name="eshop">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0510" published="2003-08-07" name="CVE-2003-0510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105709355110281&amp;w=2" source="BUGTRAQ" adv="1">20030701 ezbounce[v1.0-(1.04a/1.50pre6)]: remote format string exploit.</ref>
      <ref url="http://druglord.freelsd.org/ezbounce/" source="CONFIRM">http://druglord.freelsd.org/ezbounce/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezbounce" name="ezbounce">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.23" />
        <vers num="1.24" />
        <vers num="1.25" />
        <vers num="1.26" />
        <vers num="1.27" />
        <vers num="1.28" />
        <vers num="1.29" />
        <vers num="1.3" />
        <vers num="1.30" />
        <vers num="1.31" />
        <vers num="1.32" />
        <vers num="1.33" />
        <vers num="1.34" />
        <vers num="1.35" />
        <vers num="1.36" />
        <vers num="1.37" />
        <vers num="1.38" />
        <vers num="1.39" />
        <vers num="1.4" />
        <vers num="1.40" />
        <vers num="1.41" />
        <vers num="1.42" />
        <vers num="1.43" />
        <vers num="1.44" />
        <vers num="1.45" />
        <vers num="1.46" />
        <vers num="1.47" />
        <vers num="1.48" />
        <vers num="1.49" />
        <vers num="1.5" />
        <vers num="1.50" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0511" published="2003-08-27" name="CVE-2003-0511" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm" source="MISC">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030728-ap1x00.shtml" source="CISCO">20030728 HTTP GET Vulnerability in AP1x00</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5834" source="OVAL">oval:org.mitre.oval:def:5834</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0055.html" source="VULNWATCH" adv="1">20030728 Cisco Aironet AP 1100 Malformed HTTP Request Crash Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(11)ja" />
        <vers num="12.2(4)ja" />
        <vers num="12.2(4)ja1" />
        <vers num="12.2(8)ja" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0512" published="2003-08-27" name="CVE-2003-0512" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/886796" source="CERT-VN">VU#886796</ref>
      <ref url="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm" source="MISC">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml" source="CISCO">20030724 Enumerating Locally Defined Users in Cisco IOS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5824" source="OVAL">oval:org.mitre.oval:def:5824</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0056.html" source="VULNWATCH" adv="1">20030728 Cisco Aironet AP1100 Valid Account Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(24)s1" />
        <vers num="12.0(24.2)s" />
        <vers num="12.2(11)ja1" />
        <vers num="12.2(14.5)" />
        <vers num="12.2(14.5)t" />
        <vers num="12.2(15)zn" />
        <vers num="12.2(15.1)s" />
        <vers num="12.2(16)b" />
        <vers num="12.2(16.1)b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0513" published="2004-04-15" name="CVE-2003-0513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0514" published="2004-04-15" name="CVE-2003-0514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0515" published="2003-08-18" name="CVE-2003-0515" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-347" source="DEBIAN" patch="1" adv="1">DSA-347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teapop" name="teapop">
        <vers num="0.3.4" />
        <vers num="0.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0516" published="2003-08-18" name="CVE-2003-0516" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" source="CONFIRM" patch="1">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gert_doering" name="mgetty">
        <vers prev="1" num="1.1.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0517" published="2003-08-18" name="CVE-2003-0517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" source="CONFIRM">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gert_doering" name="mgetty">
        <vers num="1.1.19" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22" />
        <vers prev="1" num="1.1.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0518" published="2003-08-18" name="CVE-2003-0518" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0187.html" source="BUGTRAQ" patch="1">20030715 FIXED: MacOSX - crash screensaver locked with password and get thedesktop back</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=120232" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=120232</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0034.html" source="BUGTRAQ" adv="1">20030704 MacOSX - crash screensaver locked with password and get the desktop back</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0519" published="2003-08-18" name="CVE-2003-0519" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006286.html" source="FULLDISC">20030707 Internet Explorer 6 DoS Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0520" published="2003-08-18" name="CVE-2003-0520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8107" source="BID" adv="1">8107</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105735714318026&amp;w=2" source="BUGTRAQ" adv="1">20030704 Trillian Remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="0.74" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0521" published="2003-08-18" name="CVE-2003-0521" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
cPanel, cPanel, 7.0</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105760556627616&amp;w=2" source="BUGTRAQ" patch="1">20030706 cPanel Malicious HTML Tags Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0522" published="2003-08-18" name="CVE-2003-0522" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105760660928715&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030705 Re: Another ProductCart SQL Injection Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105733145930031&amp;w=2" source="BUGTRAQ" adv="1">20030704 Another ProductCart SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="1.5" />
        <vers num="1.5002" />
        <vers num="1.5003" />
        <vers num="1.5003r" />
        <vers num="1.5004" />
        <vers num="1.6002" />
        <vers num="1.6003" />
        <vers num="1.6b" />
        <vers num="1.6b001" />
        <vers num="1.6b002" />
        <vers num="1.6b003" />
        <vers num="1.6br" />
        <vers num="1.6br001" />
        <vers num="1.6br003" />
        <vers num="2" />
        <vers num="2br000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0523" published="2003-08-18" name="CVE-2003-0523" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105761696706800&amp;w=2" source="BUGTRAQ" adv="1">20030705 ProductCart XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="1.5" />
        <vers num="1.5002" />
        <vers num="1.5003" />
        <vers num="1.5003r" />
        <vers num="1.5004" />
        <vers num="1.6002" />
        <vers num="1.6003" />
        <vers num="1.6b" />
        <vers num="1.6b001" />
        <vers num="1.6b002" />
        <vers num="1.6b003" />
        <vers num="1.6br" />
        <vers num="1.6br001" />
        <vers num="1.6br003" />
        <vers num="2" />
        <vers num="2br000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0524" published="2003-08-18" name="CVE-2003-0524" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105769387706906&amp;w=2" source="BUGTRAQ" adv="1">20030708 Qt temporary files race condition in Knoppix 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knoppix" name="knoppix">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0525" published="2003-08-27" name="CVE-2003-0525" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12701" source="XF">winnt-file-management-dos (12701)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-029.asp" source="MS">MS03-029</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a072303-1.txt" source="ATSTAKE" adv="1">A072303-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:319" source="OVAL" sig="1">oval:org.mitre.oval:def:319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0526" published="2003-08-18" name="CVE-2003-0526" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-028.asp" source="MS">MS03-028</ref>
      <ref url="http://pivx.com/larholm/adv/TL006" source="MISC">http://pivx.com/larholm/adv/TL006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105838590030409&amp;w=2" source="NTBUGTRAQ">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838519729525&amp;w=2" source="BUGTRAQ">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html" source="VULNWATCH">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html" source="VULNWATCH" adv="1">20030716 ISA Server - Error Page Cross Site Scripting</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838862201266&amp;w=2" source="BUGTRAQ">20030716 ISA Server - Error Page Cross Site Scripting</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:117" source="OVAL" sig="1">oval:org.mitre.oval:def:117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="fp1" />
        <vers num="2000" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0528" published="2003-09-17" name="CVE-2003-0528" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-23.html" source="CERT" patch="1" adv="1">CA-2003-23</ref>
      <ref url="http://www.kb.cert.org/vuls/id/254236" source="CERT-VN">VU#254236</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-039.asp" source="MS" patch="1" adv="1">MS03-039</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0306.htm" source="MISC">http://www.nsfocus.com/english/homepage/research/0306.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0100.html" source="VULNWATCH">20030911 NSFOCUS SA2003-06 : Microsoft Windows RPC DCOM Interface Heap Overflow Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106407417011430&amp;w=2" source="BUGTRAQ">20030920 The Analysis of RPC Long Filename Heap Overflow AND a Way to Write  Universal Heap Overflow of Windows</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3966" source="OVAL" sig="1">oval:org.mitre.oval:def:3966</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2968" source="OVAL" sig="1">oval:org.mitre.oval:def:2968</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2884" source="OVAL" sig="1">oval:org.mitre.oval:def:2884</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:127" source="OVAL" sig="1">oval:org.mitre.oval:def:127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0530" published="2003-08-27" name="CVE-2003-0530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/548964" source="CERT-VN">VU#548964</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-22.html" source="CERT">CA-2003-22</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS" patch="1" adv="1">MS03-032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12962" source="XF">ie-br549-activex-bo(12962)</ref>
      <ref url="http://www.securityfocus.com/bid/8454" source="BID" adv="1">8454</ref>
      <ref url="http://securitytracker.com/id?1007538" source="SECTRACK">1007538</ref>
      <ref url="http://secunia.com/advisories/9580" source="SECUNIA">9580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0531" published="2003-08-27" name="CVE-2003-0531" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/205148" source="CERT-VN">VU#205148</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-22.html" source="CERT">CA-2003-22</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS" patch="1" adv="1">MS03-032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12961" source="XF">ie-cache-script-injection(12961)</ref>
      <ref url="http://www.securityfocus.com/bid/8457" source="BID" adv="1">8457</ref>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/67_e.html" source="MISC">http://www.lac.co.jp/security/english/snsadv_e/67_e.html</ref>
      <ref url="http://secunia.com/advisories/9580" source="SECUNIA">9580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0532" published="2003-08-27" name="CVE-2003-0532" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/865940" source="CERT-VN" adv="1">VU#865940</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS">MS03-032</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20030820.html" source="MISC">http://www.eeye.com/html/Research/Advisories/AD20030820.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106149026621753&amp;w=2" source="BUGTRAQ" adv="1">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html" source="VULNWATCH" adv="1">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0533" published="2004-06-01" name="CVE-2003-0533" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/753212" source="CERT-VN" patch="1" adv="1">VU#753212</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413C.html" source="EEYE">AD20040413C</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108325860431471&amp;w=2" source="BUGTRAQ">20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html" source="FULLDISC">20040413 EEYE: Windows Local Security Authority Service Remote Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15699" source="XF">win-lsass-bo(15699)</ref>
      <ref url="http://www.securityfocus.com/bid/10108" source="BID">10108</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:919" source="OVAL" sig="1">oval:org.mitre.oval:def:919</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:898" source="OVAL" sig="1">oval:org.mitre.oval:def:898</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:883" source="OVAL" sig="1">oval:org.mitre.oval:def:883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0535" published="2003-08-18" name="CVE-2003-0535" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-345" source="DEBIAN" patch="1" adv="1">DSA-345</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006386.html" source="FULLDISC">20030708 Fwd: xbl vulnerabilty</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xblockout" name="xbl">
        <vers num="1.0i" />
        <vers num="1.0k" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0536" published="2003-08-18" name="CVE-2003-0536" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-346" source="DEBIAN" patch="1" adv="1">DSA-346</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105128606513226&amp;w=2" source="BUGTRAQ" adv="1">20030425 Unauthorized reading files on phpSysInfo</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsysinfo" name="phpsysinfo">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0537" published="2003-08-18" name="CVE-2003-0537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-341" source="DEBIAN" patch="1" adv="1">DSA-341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daiki_ueno" name="liece_emacs_irc_client">
        <vers prev="1" num="2.0_0.2003-05-27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0538" published="2003-08-18" name="CVE-2003-0538" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-342" source="DEBIAN" patch="1" adv="1">DSA-342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozart" name="mozart">
        <vers num="1.2.3" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0539" published="2003-08-18" name="CVE-2003-0539" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-343" source="DEBIAN" patch="1" adv="1">DSA-343</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-242.html" source="REDHAT">RHSA-2003:242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:28" source="OVAL" sig="1">oval:org.mitre.oval:def:28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ddskk" name="ddskk">
        <vers num="11.6_.rel.0" />
      </prod>
      <prod vendor="redhat" name="daredevil_skk">
        <vers num="11.3.2" edition="" />
        <vers num="11.3.2" edition=":noarch" />
        <vers num="11.3.5" edition="" />
        <vers num="11.3.5" edition=":noarch" />
        <vers num="11.6.0-10" edition="" />
        <vers num="11.6.0-10" edition=":noarch" />
        <vers num="11.6.0-6" edition="" />
        <vers num="11.6.0-6" edition=":noarch" />
        <vers num="11.6.0-8" edition="" />
        <vers num="11.6.0-8" edition=":noarch" />
      </prod>
      <prod vendor="redhat" name="ddskk-xemacs">
        <vers num="11.6.0-10" edition="" />
        <vers num="11.6.0-10" edition=":noarch" />
        <vers num="11.6.0-6" edition="" />
        <vers num="11.6.0-6" edition=":noarch" />
        <vers num="11.6.0-8" edition="" />
        <vers num="11.6.0-8" edition=":noarch" />
      </prod>
      <prod vendor="skk" name="skk">
        <vers num="10.62a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0540" published="2003-08-27" name="CVE-2003-0540" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/895508" source="CERT-VN">VU#895508</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-251.html" source="REDHAT" patch="1" adv="1">RHSA-2003:251</ref>
      <ref url="http://www.debian.org/security/2003/dsa-363" source="DEBIAN" patch="1" adv="1">DSA-363</ref>
      <ref url="http://www.securityfocus.com/bid/8333" source="BID">8333</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_033_postfix.html" source="SUSE">SuSE-SA:2003:033</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3517.html" source="ENGARDE">ESA-20030804-019</ref>
      <ref url="http://secunia.com/advisories/9433" source="SECUNIA">9433</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106029188614704&amp;w=2" source="TRUSTIX">2003-0029</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-August/007693.html" source="FULLDISC">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717" source="CONECTIVA">CLA-2003:717</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081" source="MANDRAKE">MDKSA-2003:081</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001525130257&amp;w=2" source="BUGTRAQ">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:544" source="OVAL" sig="1">oval:org.mitre.oval:def:544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wietse_venema" name="postfix">
        <vers num="1.0.21" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1999-09-06" />
        <vers num="1999-12-31" />
        <vers num="2000-02-28" />
        <vers num="2001-11-15" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0541" published="2003-09-17" name="CVE-2003-0541" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-264.html" source="REDHAT" patch="1" adv="1">RHSA-2003:264</ref>
      <ref url="http://www.debian.org/security/2005/dsa-710" source="DEBIAN">DSA-710</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:093" source="MANDRAKE">MDKSA-2003:093</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" source="CONECTIVA">CLA-2003:737</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:148" source="OVAL" sig="1">oval:org.mitre.oval:def:148</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gtkhtml">
        <vers prev="1" num="1.1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0542" published="2003-11-03" name="CVE-2003-0542" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/549142" source="CERT-VN">VU#549142</ref>
      <ref url="http://www.kb.cert.org/vuls/id/434566" source="CERT-VN">VU#434566</ref>
      <ref url="http://www.securityfocus.com/bid/8911" source="BID" patch="1" adv="1">8911</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-015.html" source="REDHAT" patch="1" adv="1">RHSA-2004:015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106761802305141&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031031 GLSA:  apache (200310-04)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13400" source="XF">apache-modalias-modrewrite-bo(13400)</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://www.securityfocus.com/archive/1/342674" source="BUGTRAQ">20031028 [OpenPKG-SA-2003.046] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://www.securityfocus.com/advisories/6079" source="HP">HPSBUX0311-301</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-405.html" source="REDHAT">RHSA-2003:405</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-360.html" source="REDHAT">RHSA-2003:360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-320.html" source="REDHAT">RHSA-2003:320</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103" source="MANDRAKE">MDKSA-2003:103</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" source="SUNALERT">101841</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101444-1" source="SUNALERT">101444</ref>
      <ref url="http://secunia.com/advisories/10593" source="SECUNIA">10593</ref>
      <ref url="http://secunia.com/advisories/10580" source="SECUNIA">10580</ref>
      <ref url="http://secunia.com/advisories/10463" source="SECUNIA">10463</ref>
      <ref url="http://secunia.com/advisories/10264" source="SECUNIA">10264</ref>
      <ref url="http://secunia.com/advisories/10260" source="SECUNIA">10260</ref>
      <ref url="http://secunia.com/advisories/10153" source="SECUNIA">10153</ref>
      <ref url="http://secunia.com/advisories/10114" source="SECUNIA">10114</ref>
      <ref url="http://secunia.com/advisories/10112" source="SECUNIA">10112</ref>
      <ref url="http://secunia.com/advisories/10102" source="SECUNIA">10102</ref>
      <ref url="http://secunia.com/advisories/10098" source="SECUNIA">10098</ref>
      <ref url="http://secunia.com/advisories/10096" source="SECUNIA">10096</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9458" source="OVAL">oval:org.mitre.oval:def:9458</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
      <ref url="http://httpd.apache.org/dist/httpd/Announcement2.html" source="CONFIRM">http://httpd.apache.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031203-01-U.asc" source="SGI">20031203-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" source="SCO">SCOSA-2004.6</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:864" source="OVAL" sig="1">oval:org.mitre.oval:def:864</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:863" source="OVAL" sig="1">oval:org.mitre.oval:def:863</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3799" source="OVAL" sig="1">oval:org.mitre.oval:def:3799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.14" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.6" />
        <vers num="1.3.9" />
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0543" published="2003-11-17" name="CVE-2003-0543" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/255484" source="CERT-VN">VU#255484</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-26.html" source="CERT">CA-2003-26</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-291.html" source="REDHAT" patch="1" adv="1">RHSA-2003:291</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3900" source="VUPEN">ADV-2006-3900</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm" source="MISC">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-292.html" source="REDHAT">RHSA-2003:292</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html" source="ENGARDE">ESA-20030930-027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-394" source="DEBIAN">DSA-394</ref>
      <ref url="http://www.debian.org/security/2003/dsa-393" source="DEBIAN">DSA-393</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1" source="SUNALERT">201029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5292" source="OVAL">oval:org.mitre.oval:def:5292</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" source="CONFIRM" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref url="http://secunia.com/advisories/22249" source="SECUNIA">22249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4254" source="OVAL" sig="1">oval:org.mitre.oval:def:4254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0544" published="2003-11-17" name="CVE-2003-0544" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/380864" source="CERT-VN">VU#380864</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-26.html" source="CERT">CA-2003-26</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-292.html" source="REDHAT" patch="1" adv="1">RHSA-2003:292</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-291.html" source="REDHAT" patch="1" adv="1">RHSA-2003:291</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3900" source="VUPEN">ADV-2006-3900</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm" source="MISC">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html" source="ENGARDE">ESA-20030930-027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-394" source="DEBIAN">DSA-394</ref>
      <ref url="http://www.debian.org/security/2003/dsa-393" source="DEBIAN">DSA-393</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1" source="SUNALERT">201029</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43041" source="XF">openssl-asn1-sslclient-dos(43041)</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref url="http://secunia.com/advisories/22249" source="SECUNIA">22249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4574" source="OVAL" sig="1">oval:org.mitre.oval:def:4574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0545" published="2003-11-17" name="CVE-2003-0545" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/935264" source="CERT-VN">VU#935264</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-26.html" source="CERT">CA-2003-26</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-292.html" source="REDHAT" patch="1" adv="1">RHSA-2003:292</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3900" source="VUPEN">ADV-2006-3900</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
      <ref url="http://www.debian.org/security/2003/dsa-394" source="DEBIAN">DSA-394</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref url="http://secunia.com/advisories/22249" source="SECUNIA" adv="1">22249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2590" source="OVAL" sig="1">oval:org.mitre.oval:def:2590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0546" published="2003-08-27" name="CVE-2003-0546" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106036724315539&amp;w=2" source="REDHAT" patch="1" adv="1">RHSA-2003:255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:631" source="OVAL" sig="1">oval:org.mitre.oval:def:631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="up2date">
        <vers num="3.0.7-1" edition="" />
        <vers num="3.0.7-1" edition=":i386" />
        <vers num="3.0.7-1" edition=":i386_gnome" />
        <vers num="3.1.23-1" edition="" />
        <vers num="3.1.23-1" edition=":i386_gnome" />
        <vers num="3.1.23-1" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0547" published="2003-08-27" name="CVE-2003-0547" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-258.html" source="REDHAT" patch="1" adv="1">RHSA-2003:258</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106194792924122&amp;w=2" source="BUGTRAQ">20030824 [slackware-security]  GDM security update (SSA:2003-236-01)</ref>
      <ref url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" source="CONFIRM">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" source="CONECTIVA">CLA-2003:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:112" source="OVAL" sig="1">oval:org.mitre.oval:def:112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.4.1" />
        <vers num="2.4.1.1" />
        <vers num="2.4.1.2" />
        <vers num="2.4.1.3" />
        <vers num="2.4.1.4" />
        <vers num="2.4.1.5" />
        <vers num="2.4.1.6" />
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="2.4.0.7.13" edition="" />
        <vers num="2.4.0.7.13" edition=":i386" />
        <vers num="2.4.1.3.5" edition="" />
        <vers num="2.4.1.3.5" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0548" published="2003-08-27" name="CVE-2003-0548" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-259.html" source="REDHAT" patch="1" adv="1">RHSA-2003:259</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-258.html" source="REDHAT" patch="1" adv="1">RHSA-2003:258</ref>
      <ref url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" source="CONFIRM">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" source="CONECTIVA">CLA-2003:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:113" source="OVAL" sig="1">oval:org.mitre.oval:def:113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.2.0" />
        <vers num="2.4.1" />
        <vers num="2.4.1.1" />
        <vers num="2.4.1.2" />
        <vers num="2.4.1.3" />
        <vers num="2.4.1.4" />
        <vers num="2.4.1.5" />
        <vers num="2.4.1.6" />
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="2.0_beta2.45" edition="" />
        <vers num="2.0_beta2.45" edition=":ppc" />
        <vers num="2.0_beta2.45" edition=":i386" />
        <vers num="2.2.3.1.20" edition="" />
        <vers num="2.2.3.1.20" edition=":ia64" />
        <vers num="2.2.3.1.20" edition=":i386" />
        <vers num="2.2.3.1.22" edition="" />
        <vers num="2.2.3.1.22" edition=":i386" />
        <vers num="2.4.0.7.13" edition="" />
        <vers num="2.4.0.7.13" edition=":i386" />
        <vers num="2.4.1.3.5" edition="" />
        <vers num="2.4.1.3.5" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0549" published="2003-08-27" name="CVE-2003-0549" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-259.html" source="REDHAT" patch="1" adv="1">RHSA-2003:259</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-258.html" source="REDHAT" patch="1" adv="1">RHSA-2003:258</ref>
      <ref url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" source="CONFIRM">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" source="CONECTIVA">CLA-2003:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:129" source="OVAL" sig="1">oval:org.mitre.oval:def:129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.2.0" />
        <vers num="2.4.1" />
        <vers num="2.4.1.1" />
        <vers num="2.4.1.2" />
        <vers num="2.4.1.3" />
        <vers num="2.4.1.4" />
        <vers num="2.4.1.5" />
        <vers num="2.4.1.6" />
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="2.0_beta2.45" edition="" />
        <vers num="2.0_beta2.45" edition=":ppc" />
        <vers num="2.0_beta2.45" edition=":i386" />
        <vers num="2.2.3.1.20" edition="" />
        <vers num="2.2.3.1.20" edition=":ia64" />
        <vers num="2.2.3.1.20" edition=":i386" />
        <vers num="2.2.3.1.22" edition="" />
        <vers num="2.2.3.1.22" edition=":i386" />
        <vers num="2.4.0.7.13" edition="" />
        <vers num="2.4.0.7.13" edition=":i386" />
        <vers num="2.4.1.3.5" edition="" />
        <vers num="2.4.1.3.5" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0550" published="2003-08-27" name="CVE-2003-0550" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:380" source="OVAL" sig="1">oval:org.mitre.oval:def:380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0551" published="2003-08-27" name="CVE-2003-0551" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:384" source="OVAL" sig="1">oval:org.mitre.oval:def:384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0552" published="2003-08-27" name="CVE-2003-0552" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT" patch="1" adv="1">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:385" source="OVAL" sig="1">oval:org.mitre.oval:def:385</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0553" published="2003-08-18" name="CVE-2003-0553" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820193406838&amp;w=2" source="BUGTRAQ" adv="1">20030714 Netscape 7.02 Client Detection Tool plug-in buffer overrun</ref>
      <ref url="http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf" source="MISC">http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0554" published="2003-08-18" name="CVE-2003-0554" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820316708258&amp;w=2" source="BUGTRAQ" adv="1">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006505.html" source="FULLDISC">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neomodus" name="direct_connect">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0555" published="2003-08-18" name="CVE-2003-0555" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820576111599&amp;w=2" source="BUGTRAQ" adv="1">20030714 ImageMagick's Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0556" published="2003-08-18" name="CVE-2003-0556" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105804648003163&amp;w=2" source="BUGTRAQ" adv="1">20030712 DoS - Polycom MGC 25 Control Port</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006494.html" source="FULLDISC">20030712 DoS - Polycom MGC 25 Control Port</ref>
    </refs>
    <vuln_soft>
      <prod vendor="polycom" name="mgc-100">
        <vers num="" />
      </prod>
      <prod vendor="polycom" name="mgc-25">
        <vers num="5.51.21" />
        <vers num="5.51.211" />
      </prod>
      <prod vendor="polycom" name="mgc-50">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0557" published="2003-08-18" name="CVE-2003-0557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.</descript>
    </desc>
    <sols>
      <sol source="nvd">This issue was addressed in a hot fix for StoreFront 6.1 in late January 2004.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105804683203384&amp;w=2" source="BUGTRAQ">20030712 ZH2003-3SA (security advisory): Storefront sql injection: users</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lagarde" name="storefront">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0558" published="2003-08-18" name="CVE-2003-0558" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105795219412333&amp;w=2" source="BUGTRAQ" adv="1">20030711 LeapFTP remote buffer overflow exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leapware" name="leapftp">
        <vers num="2.7.3.600" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0559" published="2003-08-18" name="CVE-2003-0559" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105787021803729&amp;w=2" source="BUGTRAQ" adv="1">20030710 PHP-Include-Hack-Possibility in phpforum 2 RC-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpforum" name="phpforum">
        <vers num="2.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0560" published="2003-08-18" name="CVE-2003-0560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105733277731084&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030704 VPASP SQL Injection Vulnerability &amp; Exploit CODE</ref>
      <ref url="http://www.securityfocus.com/bid/8159" source="BID" adv="1">8159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_programming" name="vp-asp">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0561" published="2003-08-18" name="CVE-2003-0561" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105769805311484&amp;w=2" source="BUGTRAQ">20030707 Multiple Buffer Overflows in IglooFTP PRO</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0010.html" source="VULNWATCH">20030707 Multiple Buffer Overflows in IglooFTP PRO</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iglooftp" name="iglooftp_pro">
        <vers num="3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0562" published="2003-08-27" name="CVE-2003-0562" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/185593" source="CERT-VN">VU#185593</ref>
      <ref url="http://www.protego.dk/advisories/200301.html" source="MISC">http://www.protego.dk/advisories/200301.html</ref>
      <ref url="http://support.novell.com/servlet/tidfinder/2966549" source="CONFIRM">http://support.novell.com/servlet/tidfinder/2966549</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105897724931665&amp;w=2" source="BUGTRAQ" adv="1">20030723 Buffer Overflow in Netware Web Server PERL Handler</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0041.html" source="VULNWATCH">20030723 Buffer Overflow in Netware Web Server PERL Handler</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105897561229347&amp;w=2" source="BUGTRAQ">20030723 NOVL-2003-2966549 - Enterprise Web Server PERL Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" edition="sp4" />
        <vers num="5.1" edition="sp6" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0564" published="2003-12-01" name="CVE-2003-0564" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/428230" source="CERT-VN" adv="1">VU#428230</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/smime.htm" source="MISC" patch="1" adv="1">http://www.uniras.gov.uk/vuls/2003/006489/smime.htm</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-110.html" source="REDHAT" patch="1" adv="1">RHSA-2004:110</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2" source="HP" patch="1" adv="1">SSRT4722</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13603" source="XF">smime-asn1-bo(13603)</ref>
      <ref url="http://www.securityfocus.com/bid/8981" source="BID" adv="1">8981</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-112.html" source="REDHAT">RHSA-2004:112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11462" source="OVAL">oval:org.mitre.oval:def:11462</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040402-01-U.asc" source="SGI">20040402-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" source="MANDRAKE">MDKSA-2004:021</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:914" source="OVAL" sig="1">oval:org.mitre.oval:def:914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:872" source="OVAL" sig="1">oval:org.mitre.oval:def:872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="groupmax_mail_-_security_option">
        <vers num="6.0" />
      </prod>
      <prod vendor="hitachi" name="pki_runtime_library">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0565" published="2003-12-01" name="CVE-2003-0565" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927278" source="CERT-VN" adv="1">VU#927278</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/x400.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2003/006489/x400.htm</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0567" published="2003-08-18" name="CVE-2003-0567" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-17.html" source="CERT" patch="1" adv="1">CA-2003-17</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-15.html" source="CERT" patch="1" adv="1">CA-2003-15</ref>
      <ref url="http://www.kb.cert.org/vuls/id/411332" source="CERT-VN">VU#411332</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml" source="CISCO">20030717 IOS Interface Blocked by IPv4 Packet</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5603" source="OVAL">oval:org.mitre.oval:def:5603</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006743.html" source="FULLDISC">20030718 (no subject)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="11.1aa" />
        <vers num="11.1ca" />
        <vers num="11.1cc" />
        <vers num="11.2" />
        <vers num="11.2p" />
        <vers num="11.2sa" />
        <vers num="11.3" />
        <vers num="11.3t" />
        <vers num="12.0" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w5" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xp" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xu" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1m" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xk" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ja" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2mx" />
        <vers num="12.2s" />
        <vers num="12.2sx" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="3.0" />
        <vers num="3.1_.0" />
        <vers num="3.2_.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0572" published="2003-08-18" name="CVE-2003-0572" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12635" source="XF">irix-nsd-map-dos(12635)</ref>
      <ref url="http://www.osvdb.org/8587" source="OSVDB">8587</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0573" published="2003-08-18" name="CVE-2003-0573" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0574" published="2003-08-18" name="CVE-2003-0574" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030702-01-P" source="SGI" patch="1" adv="1">20030702-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17" />
        <vers num="6.5.18" />
        <vers num="6.5.19" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0575" published="2003-08-27" name="CVE-2003-0575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the name services daemon (nsd) in SGI IRIX 6.5.x through 6.5.21f, and possibly earlier versions, allows attackers to gain root privileges via the AUTH_UNIX gid list.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/682900" source="CERT-VN">VU#682900</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030704-01-P" source="SGI" patch="1" adv="1">20030704-01-P</ref>
      <ref url="http://www.securityfocus.com/bid/8304" source="BID" adv="1">8304</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105958240709302&amp;w=2" source="BUGTRAQ" adv="1">20030730 [LSD] IRIX nsd remote buffer overflow vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12763" source="XF">irix-authunix-nsd-bo(12763)</ref>
      <ref url="http://www.osvdb.org/2337" source="OSVDB">2337</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-130.shtml" source="CIAC">N-130</ref>
      <ref url="http://secunia.com/advisories/9390" source="SECUNIA">9390</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0576" published="2003-08-27" name="CVE-2003-0576" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, a different vulnerability than CVE-2003-0619.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030801-02-P" source="SGI">20030801-02-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030801-01-P" source="SGI">20030801-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0577" published="2003-08-18" name="CVE-2003-0577" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6629" source="BID" patch="1" adv="1">6629</ref>
      <ref url="http://www.securityfocus.com/archive/1/306903" source="BUGTRAQ" patch="1">20030116 Re[2]: Local/remote mpg123 exploit</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000695" source="CONECTIVA" adv="1">CLA-2003:695</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt" source="SCO">CSSA-2004-002.0</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:078" source="MANDRAKE">MDKSA-2003:078</ref>
      <ref url="http://secunia.com/advisories/7875" source="SECUNIA">7875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59r" />
        <vers num="pre0.59s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0578" published="2003-08-18" name="CVE-2003-0578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839150004682&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html" source="VULNWATCH" adv="1">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="u2_universe">
        <vers prev="1" num="10.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0579" published="2003-08-18" name="CVE-2003-0579" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html" source="VULNWATCH" adv="1">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838948002337&amp;w=2" source="BUGTRAQ">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="u2_universe">
        <vers prev="1" num="10.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0580" published="2003-08-18" name="CVE-2003-0580" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0028.html" source="VULNWATCH" patch="1" adv="1">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839042603476&amp;w=2" source="BUGTRAQ">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="u2_universe">
        <vers prev="1" num="10.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0581" published="2003-08-18" name="CVE-2003-0581" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-360" source="DEBIAN" patch="1" adv="1">DSA-360</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105829691405446&amp;w=2" source="BUGTRAQ" adv="1">20030714 xfstt-1.4 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfstt" name="xfstt">
        <vers num="1.2.1" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0582" reject="1" published="2003-12-31" name="CVE-2003-0582" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0504.  Reason: This candidate is a duplicate of CVE-2003-0504.  Notes: All CVE users should reference CVE-2003-0504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0583" published="2003-08-18" name="CVE-2003-0583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105846288808846&amp;w=2" source="BUGTRAQ" adv="1">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tolis_group" name="bru">
        <vers prev="1" num="17.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0584" published="2003-08-18" name="CVE-2003-0584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105846288808846&amp;w=2" source="BUGTRAQ" adv="1">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tolis_group" name="bru">
        <vers prev="1" num="17.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0585" published="2003-08-18" name="CVE-2003-0585" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105845898003616&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brooky" name="estore">
        <vers num="1.0.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0586" published="2003-08-18" name="CVE-2003-0586" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105845898003616&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brooky" name="estore">
        <vers num="1.0.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0587" published="2003-08-18" name="CVE-2003-0587" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839276105934&amp;w=2" source="BUGTRAQ">20030716 Changing UBB cookie allows account hijack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopop" name="ultimate_bulletin_board">
        <vers num="6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0588" published="2003-08-18" name="CVE-2003-0588" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839007002993&amp;w=2" source="BUGTRAQ" adv="1">20030716 Digi-news and Digi-ads version 1.1 admin access without password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digi-fx" name="digi-news">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0589" published="2003-08-18" name="CVE-2003-0589" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839007002993&amp;w=2" source="BUGTRAQ" adv="1">20030716 Digi-news and Digi-ads version 1.1 admin access without password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digi-fx" name="digi-news">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0590" published="2003-08-18" name="CVE-2003-0590" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://members.fortunecity.it/lethalman2002/bugs/splatt.html" source="MISC">http://members.fortunecity.it/lethalman2002/bugs/splatt.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830019209609&amp;w=2" source="BUGTRAQ">20030715 Splatt Forum html injection code in post icon</ref>
    </refs>
    <vuln_soft>
      <prod vendor="splatt" name="splatt_forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0591" reject="1" published="2003-08-27" name="CVE-2003-0591" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a duplicate number that was created during the refinement phase.  Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0592" published="2004-04-15" name="CVE-2003-0592" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-074.html" source="REDHAT" patch="1" adv="1">RHSA-2004:074</ref>
      <ref url="http://www.debian.org/security/2004/dsa-459" source="DEBIAN" patch="1" adv="1">DSA-459</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:022" source="MANDRAKE">MDKSA-2004:022</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:823" source="OVAL" sig="1">oval:org.mitre.oval:def:823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0593" published="2004-04-15" name="CVE-2003-0593" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux" />
        <vers num="5.0" edition=":mac" />
        <vers num="5.0.2" edition="" />
        <vers num="5.0.2" edition=":win32" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":win32" />
        <vers num="5.1.1" edition="" />
        <vers num="5.1.1" edition=":win32" />
        <vers num="5.12" edition="" />
        <vers num="5.12" edition=":win32" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0594" published="2004-04-15" name="CVE-2003-0594" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9826" source="OVAL">oval:org.mitre.oval:def:9826</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-112.html" source="REDHAT">RHSA-2004:112</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" source="MANDRAKE">MDKSA-2004:021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:917" source="OVAL" sig="1">oval:org.mitre.oval:def:917</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:873" source="OVAL" sig="1">oval:org.mitre.oval:def:873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0595" published="2003-08-27" name="CVE-2003-0595" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0038.html" source="VULNWATCH" adv="1">20030718 Witango &amp; Tango 2000 Application Server Remote System Buffer Overrun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="witango" name="tango_server">
        <vers num="2000" />
      </prod>
      <prod vendor="witango" name="witango_server">
        <vers num="5.0.1.061" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0596" published="2003-08-27" name="CVE-2003-0596" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if they already exist, which allows local users to read or modify files of other fdclone users by creating the directory ahead of time.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105897525828829&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-352</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=186219" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=186219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fdclone" name="fdclone">
        <vers num="2.00a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0597" published="2003-08-27" name="CVE-2003-0597" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105889063714201&amp;w=2" source="SCO" patch="1" adv="1">CSSA-2003-SCO-11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0598" reject="1" published="2003-08-27" name="CVE-2003-0598" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0657.  Reason: This candidate is a reservation duplicate of CVE-2003-0657.  Notes: All CVE users should reference CVE-2003-0657 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0599" published="2003-08-27" name="CVE-2003-0599" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web document root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpgroupware.org" source="CONFIRM">http://www.phpgroupware.org</ref>
      <ref url="http://www.debian.org/security/2003/dsa-365" source="DEBIAN">DSA-365</ref>
      <ref url="http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html" source="CONFIRM">http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers prev="1" num="0.9.14.004" />
        <vers num="0.9.16prerc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0601" published="2004-03-29" name="CVE-2003-0601" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12728" source="XF" patch="1" adv="1">macos-workgroup-gain-access(12728)</ref>
      <ref url="http://www.securityfocus.com/bid/8266" source="BID" patch="1" adv="1">8266</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=25631" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=25631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0602" published="2003-08-27" name="CVE-2003-0602" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6868" source="BID" patch="1" adv="1">6868</ref>
      <ref url="http://www.securityfocus.com/bid/6861" source="BID" patch="1" adv="1">6861</ref>
      <ref url="http://www.bugzilla.org/security/2.16.2/" source="CONFIRM">http://www.bugzilla.org/security/2.16.2/</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000653" source="CONECTIVA">CLA-2003:653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0603" published="2003-08-27" name="CVE-2003-0603" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7412" source="BID" patch="1" adv="1">7412</ref>
      <ref url="http://www.bugzilla.org/security/2.16.2/" source="CONFIRM">http://www.bugzilla.org/security/2.16.2/</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000653" source="CONECTIVA" adv="1">CLA-2003:653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0604" published="2003-08-27" name="CVE-2003-0604" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pivx.com/larholm/unpatched/" source="MISC">http://www.pivx.com/larholm/unpatched/</ref>
      <ref url="http://www.malware.com/once.again%21.html" source="MISC">http://www.malware.com/once.again!.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105899408520292&amp;w=2" source="NTBUGTRAQ" adv="1">20030723 Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105899261818572&amp;w=2" source="BUGTRAQ" adv="1">20030723 Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105906261314411&amp;w=2" source="NTBUGTRAQ">20030723 Re: Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105906867322856&amp;w=2" source="BUGTRAQ">20030723 Re: Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0605" published="2003-08-27" name="CVE-2003-0605" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/326746" source="CERT-VN">VU#326746</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-23.html" source="CERT">CA-2003-23</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-19.html" source="CERT">CA-2003-19</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-039.asp" source="MS">MS03-039</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105880332428706&amp;w=2" source="BUGTRAQ" adv="1">20030720 Microsoft Windows 2000 RPC DCOM Interface DOS AND Privilege Escalation Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006851.html" source="FULLDISC">20030721 Microsoft Windows 2000 RPC DCOM Interface DOS AND Privilege Escalation Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:494" source="OVAL" sig="1">oval:org.mitre.oval:def:494</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1118" source="OVAL" sig="1">oval:org.mitre.oval:def:1118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0606" published="2003-08-27" name="CVE-2003-0606" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-353" source="DEBIAN" patch="1" adv="1">DSA-353</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvsup" name="cvsup-mirror">
        <vers num="1.2" />
      </prod>
      <prod vendor="sup" name="sup">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0607" published="2004-03-29" name="CVE-2003-0607" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12765" source="XF" patch="1" adv="1">xconq-user-display-bo(12765)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-354" source="DEBIAN" patch="1" adv="1">DSA-354</ref>
      <ref url="http://www.securityfocus.com/bid/8307" source="BID" adv="1">8307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stanley_t._shebs" name="xconq">
        <vers num="7.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0609" published="2003-08-27" name="CVE-2003-0609" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105951760418667&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030729 Solaris ld.so.1 buffer overflow</ref>
      <ref url="http://www.idefense.com/advisory/07.29.03.txt" source="IDEFENSE">20030729 Buffer Overflow in Sun Solaris Runtime Linker</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55680" source="SUNALERT">55680</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12755" source="XF">sun-ldso1-ldpreload-bo(12755)</ref>
      <ref url="http://www.osvdb.org/8722" source="OSVDB">8722</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3601" source="OVAL" sig="1">oval:org.mitre.oval:def:3601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0610" published="2003-08-27" name="CVE-2003-0610" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" source="CONFIRM" patch="1" adv="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0611" published="2003-08-27" name="CVE-2003-0611" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8312" source="BID" patch="1" adv="1">8312</ref>
      <ref url="http://www.debian.org/security/2003/dsa-356" source="DEBIAN" patch="1" adv="1">DSA-356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xtokkaetama" name="xtokkaetama">
        <vers num="1.0_b6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0612" published="2004-03-29" name="CVE-2003-0612" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13017" source="XF" adv="1">crafty-long-argument-bo(13017)</ref>
      <ref url="http://secunia.com/advisories/9577/" source="SECUNIA" adv="1">9577</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15501" source="XF">crafty-command-line-bo(15501)</ref>
      <ref url="http://www.securityfocus.com/bid/9893" source="BID">9893</ref>
      <ref url="http://www.securityfocus.com/archive/1/357601" source="BUGTRAQ">20040315 Crafty Game Stack Overflow &amp; Exploit</ref>
      <ref url="http://securitytracker.com/id?1009398" source="SECTRACK">1009398</ref>
      <ref url="http://securitytracker.com/id?1009393" source="SECTRACK">1009393</ref>
      <ref url="http://packages.debian.org/changelogs/pool/non-free/c/crafty/crafty_19.15-1/changelog.txt" source="CONFIRM">http://packages.debian.org/changelogs/pool/non-free/c/crafty/crafty_19.15-1/changelog.txt</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203541" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robert_hyatt" name="crafty">
        <vers num="19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0613" published="2003-08-27" name="CVE-2003-0613" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-369" source="DEBIAN" patch="1" adv="1">DSA-369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zblast" name="zblast">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0614" published="2003-08-27" name="CVE-2003-0614" modified="2009-01-29" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-355" source="DEBIAN" patch="1" adv="1">DSA-355</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/348641/30/21790/threaded" source="BUGTRAQ">20040101 Re: Gallery v1.3.3 Cross Site Scripting Vulnerabillity</ref>
      <ref url="http://www.securityfocus.com/archive/1/330676" source="BUGTRAQ">20030727 Gallery XSS security advisory (with fix and patch instructions)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252092421469&amp;w=2" source="BUGTRAQ">20030902 GLSA:  gallery (200309-06)</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=82&amp;mode=thread&amp;order=0&amp;thold=0" source="CONFIRM">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=82&amp;mode=thread&amp;order=0&amp;thold=0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1_p1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0615" published="2003-08-27" name="CVE-2003-0615" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/246409" source="CERT-VN">VU#246409</ref>
      <ref url="http://www.securityfocus.com/bid/8231" source="BID" patch="1" adv="1">8231</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105880349328877&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030720 CGI.pm vulnerable to Cross-site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12669" source="XF">cgi-startform-xss(12669)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-256.html" source="REDHAT">RHSA-2003:256</ref>
      <ref url="http://www.debian.org/security/2003/dsa-371" source="DEBIAN">DSA-371</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:084" source="MANDRAKE">MDKSA-2003:084</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-155.shtml" source="CIAC">N-155</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101426-1" source="SUNALERT">101426</ref>
      <ref url="http://securitytracker.com/id?1007234" source="SECTRACK">1007234</ref>
      <ref url="http://secunia.com/advisories/13638" source="SECUNIA">13638</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=105875211018698&amp;w=2" source="FULLDISC">20030720 CGI.pm vulnerable to Cross-site Scripting.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018783704468&amp;w=2" source="BUGTRAQ">20030806 [OpenPKG-SA-2003.036] OpenPKG Security Advisory (perl-www)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000713" source="CONECTIVA">CLA-2003:713</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:470" source="OVAL" sig="1">oval:org.mitre.oval:def:470</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:307" source="OVAL" sig="1">oval:org.mitre.oval:def:307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi.pm" name="cgi.pm">
        <vers num="2.73" />
        <vers num="2.74" />
        <vers num="2.75" />
        <vers num="2.751" />
        <vers num="2.753" />
        <vers num="2.76" />
        <vers num="2.78" />
        <vers num="2.79" />
        <vers num="2.93" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="current" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0616" published="2003-08-27" name="CVE-2003-0616" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" source="CONFIRM">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" source="ATSTAKE" adv="1">A073103-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0" />
        <vers num="2.5" edition="sp1" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0617" published="2003-08-27" name="CVE-2003-0617" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-362" source="DEBIAN" patch="1" adv="1">DSA-362</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252097421549&amp;w=2" source="BUGTRAQ">20030902 GLSA:  mindi (200309-05)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hugo_rabson" name="mindi">
        <vers num="0.58_r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0618" published="2004-05-04" name="CVE-2003-0618" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-431" source="DEBIAN" patch="1" adv="1">DSA-431</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15012" source="XF" adv="1">suidperl-obtain-information(15012)</ref>
      <ref url="http://www.securityfocus.com/bid/9543" source="BID">9543</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perl" name="suidperl">
        <vers num="" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0619" published="2003-08-27" name="CVE-2003-0619" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105950927708272&amp;w=2" source="BUGTRAQ" adv="1">20030729 Remote Linux Kernel &lt; 2.4.21 DoS in XDR routine.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:386" source="OVAL" sig="1">oval:org.mitre.oval:def:386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0620" published="2003-08-27" name="CVE-2003-0620" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-364" source="DEBIAN" patch="1" adv="1">DSA-364</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105960276803617&amp;w=2" source="BUGTRAQ">20030730 Re: man-db[] multiple(4) vulnerabilities.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105951284512898&amp;w=2" source="BUGTRAQ" adv="1">20030729 man-db[] multiple(4) vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="man">
        <vers num="2.3.18" />
        <vers num="2.3.19" />
        <vers num="2.3.20" />
        <vers num="2.4" />
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0621" published="2003-12-01" name="CVE-2003-0621" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8931" source="BID" patch="1" adv="1">8931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106762000607681&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13559" source="XF">bea-tuxedo-file-disclosure(13559)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="tuxedo">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="7.1" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":enterprise" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":enterprise" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0622" published="2003-12-01" name="CVE-2003-0622" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8931" source="BID" patch="1" adv="1">8931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106762000607681&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13560" source="XF">bea-tuxedo-device-dos(13560)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="tuxedo">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="7.1" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":enterprise" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":enterprise" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0623" published="2003-12-01" name="CVE-2003-0623" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8931" source="BID" patch="1" adv="1">8931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106762000607681&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13561" source="XF">bea-tuxedo-filename-xss(13561)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="tuxedo">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="7.1" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":enterprise" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":enterprise" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0624" published="2003-12-01" name="CVE-2003-0624" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp" source="MISC" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13568" source="XF">bea-weblogic-interactivequery-xss(13568)</ref>
      <ref url="http://www.securityfocus.com/bid/8938" source="BID" adv="1">8938</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106761926906781&amp;w=2" source="BUGTRAQ" adv="1">20031031 Corsaire Security Advisory: BEA WebLogic example InteractiveQuery.jsp XSS issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="3.1.8" />
        <vers prev="1" num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0625" published="2003-08-27" name="CVE-2003-0625" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-360" source="DEBIAN" patch="1" adv="1">DSA-360</ref>
      <ref url="http://www.securityfocus.com/bid/8255" source="BID" adv="1">8255</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105941103709264&amp;w=2" source="BUGTRAQ" adv="1">20030727 [PAPER]: Address relay fingerprinting.</ref>
      <ref url="http://developer.berlios.de/forum/forum.php?forum_id=2819" source="CONFIRM">http://developer.berlios.de/forum/forum.php?forum_id=2819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfstt" name="xfstt">
        <vers num="1.2.1" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0626" published="2003-11-13" name="CVE-2003-0626" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.secunia.com/advisories/10225/" source="SECUNIA" patch="1" adv="1">10225</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13754" source="XF" adv="1">peoplesoft-searchcgi-directory-traversal(13754)</ref>
      <ref url="http://www.securityfocus.com/bid/9037" source="BID" adv="1">9037</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3610" source="AUSCERT">ESB-2003.0786</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013652.html" source="FULLDISC" adv="1">20031103 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0042.html" source="VULNWATCH" adv="1">20031113 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.10" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="8.15" />
        <vers num="8.16" />
        <vers num="8.17" />
        <vers num="8.18" />
        <vers num="8.19" />
        <vers num="8.20" />
        <vers num="8.4" />
        <vers num="8.40" />
        <vers num="8.41" />
        <vers num="8.42" />
        <vers num="8.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0627" published="2003-12-31" name="CVE-2003-0627" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13754" source="XF">peoplesoft-searchcgi-directory-traversal(13754)</ref>
      <ref url="http://www.securityfocus.com/bid/9038" source="BID">9038</ref>
      <ref url="http://www.secunia.com/advisories/10225/" source="SECUNIA">10225</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013652.html" source="FULLDISC">20031103 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0042.html" source="VULNWATCH">20031113 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.40" />
        <vers num="8.41" />
        <vers num="8.42" />
        <vers num="8.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0628" published="2003-12-15" name="CVE-2003-0628" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106874146204158&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031113 Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.10" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="8.15" />
        <vers num="8.16" />
        <vers num="8.17" />
        <vers num="8.18" />
        <vers num="8.19" />
        <vers num="8.20" />
        <vers num="8.4" />
        <vers num="8.40" />
        <vers num="8.41" />
        <vers num="8.42" />
        <vers num="8.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0629" published="2003-12-15" name="CVE-2003-0629" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106874146204158&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031113 Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.10" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="8.15" />
        <vers num="8.16" />
        <vers num="8.17" />
        <vers num="8.18" />
        <vers num="8.19" />
        <vers num="8.20" />
        <vers num="8.4" />
        <vers num="8.40" />
        <vers num="8.41" />
        <vers num="8.42" />
        <vers num="8.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0630" published="2003-10-20" name="CVE-2003-0630" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-359" source="DEBIAN" patch="1" adv="1">DSA-359</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252128221901&amp;w=2" source="BUGTRAQ">20030902 GLSA:  atari800 (200309-07)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atari800" name="atari800">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1_pre0" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0631" published="2003-08-27" name="CVE-2003-0631" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1039" source="CONFIRM">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1039</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105899875225268&amp;w=2" source="BUGTRAQ" adv="1">20030723 VMware GSX Server 2.5.1 / Workstation 4.0 (for Linux systems)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0632" published="2003-08-27" name="CVE-2003-0632" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105906721920776&amp;w=2" source="BUGTRAQ">20030724 Integrigy Security Alert - Oracle E-Business Suite FNDWRR Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="applications">
        <vers num="10.7" />
        <vers num="11.0" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.1" />
        <vers num="11.2" />
        <vers num="11.3" />
        <vers num="11.4" />
        <vers num="11.5" />
        <vers num="11.6" />
        <vers num="11.7" />
        <vers num="11.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0633" published="2003-08-27" name="CVE-2003-0633" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/8268" source="BID">8268</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105906689120237&amp;w=2" source="BUGTRAQ">20030724 Integrigy Security Alert - Oracle E-Business Suite AOL/J Setup Test Information Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="applications">
        <vers num="10.7" />
        <vers num="11.0" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.1" />
        <vers num="11.2" />
        <vers num="11.3" />
        <vers num="11.4" />
        <vers num="11.5" />
        <vers num="11.6" />
        <vers num="11.7" />
        <vers num="11.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0634" published="2003-08-27" name="CVE-2003-0634" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/936868" source="CERT-VN">VU#936868</ref>
      <ref url="http://www.securityfocus.com/bid/8267" source="BID" patch="1" adv="1">8267</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105914979629857&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030725 Oracle Extproc Buffer Overflow (#NISR25072003)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12721" source="XF">oracle-extproc-bo(12721)</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105915485303327&amp;w=2" source="NTBUGTRAQ">20030725 Oracle Extproc Buffer Overflow (#NISR25072003)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105916455814904&amp;w=2" source="BUGTRAQ">20030725 question about oracle advisory</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0105.html" source="VULNWATCH">20030912 Update to the Oracle EXTPROC advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0635" published="2003-08-27" name="CVE-2003-0635" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105492852131747&amp;w=2" source="BUGTRAQ" adv="1">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0636" published="2003-08-27" name="CVE-2003-0636" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0637" published="2003-08-27" name="CVE-2003-0637" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0638" published="2003-08-27" name="CVE-2003-0638" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND) and possibly execute arbitrary code via (1) a long user name or (2) an unknown attack related to a "special script against login."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105492852131747&amp;w=2" source="BUGTRAQ">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105492847631711&amp;w=2" source="BUGTRAQ">20030606 NOVL-2003-2966207 - iChain 2.1 Field Patch 3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.1" edition="sp1" />
        <vers num="2.1" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0639" published="2003-08-27" name="CVE-2003-0639" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105492852131747&amp;w=2" source="BUGTRAQ">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="ichain">
        <vers num="2.1" edition="sp1" />
        <vers num="2.1" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0640" published="2003-08-27" name="CVE-2003-0640" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.secunia.com/advisories/9232/" source="SECUNIA" patch="1" adv="1">9232</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0641" published="2003-08-27" name="CVE-2003-0641" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8222" source="BID" adv="1">8222</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105848106631132&amp;w=2" source="BUGTRAQ" adv="1">20030717 Bypassing ServerLock protection on Windows 2000</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12665" source="XF">serverlock-openprocess-load-module(12665)</ref>
      <ref url="http://www.osvdb.org/6578" source="OSVDB">6578</ref>
      <ref url="http://secunia.com/advisories/9310" source="SECUNIA">9310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="serverlock">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0642" published="2003-08-27" name="CVE-2003-0642" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WatchGuard ServerLock for Windows 2000 before SL 2.0.4 allows local users to access kernel memory via a symlink attack on \Device\PhysicalMemory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8223" source="BID" adv="1">8223</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105848106631132&amp;w=2" source="BUGTRAQ" adv="1">20030717 Bypassing ServerLock protection on Windows 2000</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12666" source="XF">serverlock-physicalmemory-symlink(12666)</ref>
      <ref url="http://secunia.com/advisories/9310" source="SECUNIA">9310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="serverlock">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0643" published="2003-07-25" name="CVE-2003-0643" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ultramonkey.org/bugs/cve/CAN-2003-0643.shtml" source="MISC">http://www.ultramonkey.org/bugs/cve/CAN-2003-0643.shtml</ref>
      <ref url="http://www.ultramonkey.org/bugs/cve-patch/CAN-2003-0643.patch" source="MISC">http://www.ultramonkey.org/bugs/cve-patch/CAN-2003-0643.patch</ref>
      <ref url="http://gentoo.kems.net/gentoo-x86-portage/sys-kernel/gentoo-sources/ChangeLog" source="CONFIRM">http://gentoo.kems.net/gentoo-x86-portage/sys-kernel/gentoo-sources/ChangeLog</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf" source="CONFIRM">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</ref>
      <ref url="http://secunia.com/advisories/23265" source="SECUNIA">23265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0644" published="2003-09-07" name="CVE-2003-0644" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kdbg 1.1.0 through 1.2.8 does not check permissions of the .kdbgrc file, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.kde.org/?l=kde-announce&amp;m=106296509815092&amp;w=2" source="CONFIRM" patch="1" adv="1">http://lists.kde.org/?l=kde-announce&amp;m=106296509815092&amp;w=2</ref>
      <ref url="http://lists.debian.org/debian-devel-changes/2003/09/msg00767.html" source="MLIST" adv="1">[debian-devel-changes] 20030909 Accepted kdbg 1.2.9-1 (i386 source)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-416.html" source="REDHAT">RHSA-2005:416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="johannes_sixt" name="kdbg">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0645" published="2003-08-27" name="CVE-2003-0645" modified="2008-10-23" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-364" source="DEBIAN" patch="1" adv="1">DSA-364</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12848" source="XF">mandb-opencatstream-gain-privileges(12848)</ref>
      <ref url="http://www.securityfocus.com/bid/8352" source="BID">8352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018504800341&amp;w=2" source="BUGTRAQ" adv="1">20030806 man-db[v2.4.1-]: open_cat_stream() privileged call exploit.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="man">
        <vers num="2.3.20" />
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0646" published="2003-08-27" name="CVE-2003-0646" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006488.html" source="FULLDISC">20030711 Trend Micro ActiveX Multiple Overflows</ref>
      <ref url="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionID=15274" source="CONFIRM">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionID=15274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="damage_cleanup_server">
        <vers num="1.0" />
      </prod>
      <prod vendor="trend_micro" name="housecall">
        <vers num="5.5" />
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0647" published="2003-08-27" name="CVE-2003-0647" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/579324" source="CERT-VN" patch="1" adv="1">VU#579324</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20030730-ios-2gb-get.shtml" source="CISCO" patch="1" adv="1">20030731 Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="12.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0648" published="2004-05-04" name="CVE-2003-0648" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/900964" source="CERT-VN">VU#900964</ref>
      <ref url="http://www.kb.cert.org/vuls/id/354838" source="CERT-VN">VU#354838</ref>
      <ref url="http://www.debian.org/security/2004/dsa-472" source="DEBIAN" patch="1" adv="1">DSA-472</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15726" source="XF" adv="1">ftetexteditor-vfte-bo(15726)</ref>
      <ref url="http://www.securityfocus.com/bid/10041" source="BID">10041</ref>
      <ref url="http://securitytracker.com/id?1009656" source="SECTRACK">1009656</ref>
      <ref url="http://securitytracker.com/id?1009655" source="SECTRACK">1009655</ref>
      <ref url="http://secunia.com/advisories/11290" source="SECUNIA">11290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fte" name="fte_text_editor">
        <vers num="" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0649" published="2003-08-27" name="CVE-2003-0649" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-368" source="DEBIAN" patch="1" adv="1">DSA-368</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:053" source="MANDRAKE">MDKSA-2004:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpcd" name="xpcd">
        <vers prev="1" num="2.08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0650" published="2003-08-27" name="CVE-2003-0650" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8309" source="BID" patch="1" adv="1">8309</ref>
      <ref url="http://www.gamespyarcade.com/features/versions.shtml" source="MISC">http://www.gamespyarcade.com/features/versions.shtml</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105958779017085&amp;w=2" source="BUGTRAQ" adv="1">20030730 GameSpy Arcade Arbitrary File Writing Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0064.html" source="VULNWATCH">20030730 GameSpy Arcade Arbitrary File Writing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamespy" name="arcade">
        <vers prev="1" num="1.3e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0651" published="2003-08-27" name="CVE-2003-0651" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8287" source="BID" patch="1" adv="1">8287</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0355.html" source="BUGTRAQ" patch="1" adv="1">20030728 Remotely exploitable overflow in mod_mylo for Apache</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_mylo" name="mod_mylo">
        <vers num="0.1" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0652" published="2003-08-27" name="CVE-2003-0652" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xtokkaetama allows local users to gain privileges via a long -nickname command line argument, a different vulnerability than CVE-2003-0611.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-367" source="DEBIAN" patch="1" adv="1">DSA-367</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001473329625&amp;w=2" source="BUGTRAQ" adv="1">20030803 xtokkaetama[v1.0b+]: (missed) buffer overflow exploit.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xtokkaetama" name="xtokkaetama">
        <vers num="1.0_b6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0653" published="2003-08-27" name="CVE-2003-0653" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote attackers to cause a denial of service (kernel panic or crash) via certain OSI packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-010.txt.asc" source="NETBSD">NetBSD-SA2003-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" />
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0654" published="2003-08-27" name="CVE-2003-0654" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-373" source="DEBIAN">DSA-373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autorespond" name="autorespond">
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0655" published="2003-08-27" name="CVE-2003-0655" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi is running with privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-08-01-0126.txt" source="MISC">http://www.secnetops.com/research/advisories/SRT2003-08-01-0126.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105978381618095&amp;w=2" source="BUGTRAQ" adv="1">20030801 SRT2003-08-01-0126 - cdrtools local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdrtools" name="cdrtools">
        <vers num="2.0" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0656" published="2003-08-27" name="CVE-2003-0656" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-366" source="DEBIAN" patch="1" adv="1">DSA-366</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252649028401&amp;w=2" source="BUGTRAQ" patch="1">20030902 GLSA:  eroaster (200309-04)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:083" source="MANDRAKE">MDKSA-2003:083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eroaster" name="eroaster">
        <vers num="2.0.0" />
        <vers num="2.1.0" />
        <vers num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0657" published="2003-08-27" name="CVE-2003-0657" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unauthorized database actions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-365" source="DEBIAN" patch="1" adv="1">DSA-365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers prev="1" num="0.9.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0658" published="2003-10-20" name="CVE-2003-0658" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_server">
        <vers num="3.1.1" />
      </prod>
      <prod vendor="caldera" name="openlinux_workstation">
        <vers num="3.1.1" />
      </prod>
      <prod vendor="caldera" name="openserver">
        <vers num="5.0.7" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0659" published="2003-11-17" name="CVE-2003-0659" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/967668" source="CERT-VN" patch="1" adv="1">VU#967668</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8827" source="BID" patch="1" adv="1">8827</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-045.asp" source="MS" patch="1" adv="1">MS03-045</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106632111408343&amp;w=2" source="NTBUGTRAQ">20031016 Listbox And Combobox Control Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13424" source="XF">win-user32-control-bo(13424)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106631999907035&amp;w=2" source="BUGTRAQ">20031016 Listbox And Combobox Control Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:340" source="OVAL" sig="1">oval:org.mitre.oval:def:340</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:201" source="OVAL" sig="1">oval:org.mitre.oval:def:201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0660" published="2003-11-17" name="CVE-2003-0660" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/838572" source="CERT-VN" patch="1" adv="1">VU#838572</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8830" source="BID" patch="1" adv="1">8830</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-041.asp" source="MS" patch="1" adv="1">MS03-041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13422" source="XF">win-authenticode-code-execution(13422)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:198" source="OVAL" sig="1">oval:org.mitre.oval:def:198</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:185" source="OVAL" sig="1">oval:org.mitre.oval:def:185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0661" published="2003-10-20" name="CVE-2003-0661" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/989932" source="CERT-VN">VU#989932</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-034.asp" source="MS" patch="1" adv="1">MS03-034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3483" source="OVAL" sig="1">oval:org.mitre.oval:def:3483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0662" published="2003-11-17" name="CVE-2003-0662" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/989932" source="CERT-VN" patch="1" adv="1">VU#989932</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8833" source="BID" patch="1" adv="1">8833</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-042.asp" source="MS" patch="1" adv="1">MS03-042</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0015.html" source="VULNWATCH" patch="1" adv="1">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13423" source="XF">win2k-local-troubleshooter-bo(13423)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106632192709608&amp;w=2" source="NTBUGTRAQ">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012205.html" source="FULLDISC">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:237" source="OVAL" sig="1">oval:org.mitre.oval:def:237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0663" published="2004-06-01" name="CVE-2003-0663" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/639428" source="CERT-VN" patch="1" adv="1">VU#639428</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15700" source="XF">win2k-lsass-ldap-dos(15700)</ref>
      <ref url="http://www.securityfocus.com/bid/10114" source="BID">10114</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1016" source="OVAL" sig="1">oval:org.mitre.oval:def:1016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0664" published="2003-10-20" name="CVE-2003-0664" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-035.asp" source="MS" patch="1" adv="1">MS03-035</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:188" source="OVAL" sig="1">oval:org.mitre.oval:def:188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2000" edition="sr1a" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="97" edition="sr1" />
        <vers num="97" edition="sr2" />
        <vers num="98" edition="" />
        <vers num="98" edition=":" />
        <vers num="98" edition="::japanese" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0665" published="2003-10-20" name="CVE-2003-0665" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/992132" source="CERT-VN">VU#992132</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-038.asp" source="MS" patch="1" adv="1">MS03-038</ref>
      <ref url="http://secunia.com/advisories/9668" source="SECUNIA">9668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="access">
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0666" published="2003-10-20" name="CVE-2003-0666" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-036.asp" source="MS" patch="1" adv="1">MS03-036</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106261952827573&amp;w=2" source="BUGTRAQ" adv="1">20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0092.html" source="VULNWATCH" adv="1">20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106279971612961&amp;w=2" source="BUGTRAQ">20030905 Microsoft WordPerfect Document Converter Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="wordperfect_converter">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0669" published="2003-08-27" name="CVE-2003-0669" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F47353" source="SUNALERT" patch="1" adv="1">47353</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4561" source="OVAL" sig="1">oval:org.mitre.oval:def:4561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0670" published="2003-08-27" name="CVE-2003-0670" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a080703-1.txt" source="ATSTAKE" patch="1" adv="1">A080703-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sustainable_softworks" name="ipnetmonitorx">
        <vers num="" />
      </prod>
      <prod vendor="sustainable_softworks" name="ipnetsentryx">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0671" published="2003-08-27" name="CVE-2003-0671" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a080703-1.txt" source="ATSTAKE" patch="1" adv="1">A080703-1</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a080703-2.txt" source="ATSTAKE">A080703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jeremy_elson" name="tcpflow">
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.12" />
        <vers num="0.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0672" published="2003-08-27" name="CVE-2003-0672" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-370" source="DEBIAN" patch="1" adv="1">DSA-370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leon_j_breedt" name="pam-pgsql">
        <vers num="0.5.1" />
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0676" published="2003-08-27" name="CVE-2003-0676" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106036588613929&amp;w=2" source="BUGTRAQ">20030808 Directory Traversal in Sun iPlanet Administration Server 5.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="iplanet_directory_server">
        <vers num="5.0" />
        <vers num="5.1" edition="sp1" />
        <vers num="5.1" edition="sp2" />
      </prod>
      <prod vendor="sun" name="one_directory_server">
        <vers num="5.0" edition="sp1" />
        <vers num="5.0_sp2" />
        <vers num="5.1" edition="sp1" />
        <vers num="5.1" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0677" published="2003-08-27" name="CVE-2003-0677" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM Ping failure."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/332284" source="BUGTRAQ" patch="1" adv="1">20030807 Cisco CSS 11000 Series DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0079.html" source="BUGTRAQ">20030808 Re: [VulnWatch] Cisco CSS 11000 Series DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0073.html" source="VULNWATCH" adv="1">20030807 Cisco CSS 11000 Series DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="webns">
        <vers num="5.0_0.038s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0679" published="2003-08-27" name="CVE-2003-0679" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030802-01-P" source="SGI">20030802-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers prev="1" num="6.5.21f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0680" published="2003-10-06" name="CVE-2003-0680" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030901-01-P" source="SGI">20030901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0681" published="2003-10-06" name="CVE-2003-0681" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/108964" source="CERT-VN">VU#108964</ref>
      <ref url="http://www.sendmail.org/8.12.10.html" source="CONFIRM" patch="1">http://www.sendmail.org/8.12.10.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13216" source="XF">sendmail-ruleset-parsing-bo(13216)</ref>
      <ref url="http://www.securityfocus.com/bid/8649" source="BID" adv="1">8649</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-283.html" source="REDHAT">RHSA-2003:283</ref>
      <ref url="http://www.debian.org/security/2003/dsa-384" source="DEBIAN">DSA-384</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106398718909274&amp;w=2" source="BUGTRAQ">20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106383437615742&amp;w=2" source="BUGTRAQ">20030917 GLSA:  sendmail (200309-13)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000742" source="CONECTIVA">CLA-2003:742</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:092" source="MANDRAKE">MDKSA-2003:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:595" source="OVAL" sig="1">oval:org.mitre.oval:def:595</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3606" source="OVAL" sig="1">oval:org.mitre.oval:def:3606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="advanced_message_server">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail">
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="8.10" />
        <vers num="8.10.1" />
        <vers num="8.10.2" />
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.11.6" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
        <vers num="8.12.0" />
        <vers num="8.12.1" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
        <vers num="8.12.9" />
        <vers num="8.8.8" />
        <vers num="8.9.0" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail_pro">
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail_switch">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.0.4" />
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.3" />
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":x86" />
        <vers num="1.5" edition=":sh3" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.2" />
        <vers num="3.3" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_advanced_server">
        <vers num="6.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="6.0" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0682" published="2003-10-06" name="CVE-2003-0682" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-280.html" source="REDHAT" patch="1" adv="1">RHSA-2003:280</ref>
      <ref url="http://www.debian.org/security/2003/dsa-382" source="DEBIAN" patch="1" adv="1">DSA-382</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106373546332230&amp;w=2" source="REDHAT" patch="1" adv="1">RHSA-2003:279</ref>
      <ref url="http://www.debian.org/security/2003/dsa-383" source="DEBIAN">DSA-383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381409220492&amp;w=2" source="BUGTRAQ">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000741" source="CONECTIVA">CLA-2003:741</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:446" source="OVAL" sig="1">oval:org.mitre.oval:def:446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers prev="1" num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0683" published="2003-11-03" name="CVE-2003-0683" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8921" source="BID" patch="1" adv="1">8921</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031004-01-P" source="SGI">20031004-01-P</ref>
      <ref url="http://www.osvdb.org/2734" source="OSVDB">2734</ref>
      <ref url="http://secunia.com/advisories/10095" source="SECUNIA">10095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0685" published="2003-08-27" name="CVE-2003-0685" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netris 0.52 and earlier, and possibly other versions, allows remote malicious Netris servers to execute arbitrary code on netris clients via a long server response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-372" source="DEBIAN" adv="1">DSA-372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106071059430211&amp;w=2" source="BUGTRAQ" adv="1">20030812 Netris client Buffer Overflow Vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netris" name="netris">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0686" published="2003-10-20" name="CVE-2003-0686" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/680260" source="CERT-VN">VU#680260</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-262.html" source="REDHAT" patch="1" adv="1">RHSA-2003:262</ref>
      <ref url="http://www.debian.org/security/2003/dsa-374" source="DEBIAN" patch="1" adv="1">DSA-374</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-50.txt" source="TURBO">TLSA-2003-50</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-261.html" source="REDHAT">RHSA-2003:261</ref>
      <ref url="http://us2.samba.org/samba/ftp/pam_smb/" source="CONFIRM">http://us2.samba.org/samba/ftp/pam_smb/</ref>
      <ref url="http://secunia.com/advisories/9611" source="SECUNIA">9611</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252769930090&amp;w=2" source="BUGTRAQ">20030901 GLSA:  pam_smb (200309-01)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000734" source="CONECTIVA">CLA-2003:734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:469" source="OVAL" sig="1">oval:org.mitre.oval:def:469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_airlie" name="pam_smb">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="2.0_rc4" />
      </prod>
      <prod vendor="redhat" name="pam_smb">
        <vers num="1.1.6-2" edition="" />
        <vers num="1.1.6-2" edition=":ia64" />
        <vers num="1.1.6-2" edition=":i386" />
        <vers num="1.1.6-5" edition="" />
        <vers num="1.1.6-5" edition=":i386" />
        <vers num="1.1.6-7" edition="" />
        <vers num="1.1.6-7" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0687" reject="1" published="2004-08-18" name="CVE-2003-0687" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was internally assigned to a problem that was not reachable (the affected routine was not used by the software).  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0688" published="2003-10-20" name="CVE-2003-0688" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/993452" source="CERT-VN">VU#993452</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-265.html" source="REDHAT" patch="1" adv="1">RHSA-2003:265</ref>
      <ref url="http://www.sendmail.org/dnsmap1.html" source="CONFIRM">http://www.sendmail.org/dnsmap1.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_035_sendmail.html" source="SUSE">SuSE-SA:2003:035</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030803-01-P" source="SGI">20030803-01-P</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:086" source="MANDRAKE">MDKSA-2003:086</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000727" source="CONECTIVA">CLA-2003:727</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:597" source="OVAL" sig="1">oval:org.mitre.oval:def:597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sendmail">
        <vers num="8.12.5-7" edition="" />
        <vers num="8.12.5-7" edition=":i386_doc" />
        <vers num="8.12.5-7" edition=":i386_cf" />
        <vers num="8.12.5-7" edition=":i386" />
        <vers num="8.12.5-7" edition=":i386_dev" />
        <vers num="8.12.8-4" edition="" />
        <vers num="8.12.8-4" edition=":i386" />
        <vers num="8.12.8-4" edition=":i386_cf" />
        <vers num="8.12.8-4" edition=":i386_doc" />
        <vers num="8.12.8-4" edition=":i386_dev" />
      </prod>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.12.1" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="5.0a" />
        <vers num="5.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="5.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.19" />
        <vers num="6.5.20" />
        <vers num="6.5.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0689" published="2003-10-20" name="CVE-2003-0689" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-249.html" source="REDHAT" patch="1" adv="1">RHSA-2003:249</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-325.html" source="REDHAT">RHSA-2003:325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0690" published="2003-10-06" name="CVE-2003-0690" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-270.html" source="REDHAT" patch="1" adv="1">RHSA-2003:270</ref>
      <ref url="http://www.kde.org/info/security/advisory-20030916-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20030916-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106374551513499&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-289.html" source="REDHAT">RHSA-2003:289</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-286.html" source="REDHAT">RHSA-2003:286</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://www.debian.org/security/2003/dsa-388" source="DEBIAN">DSA-388</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html" source="MISC">http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-288.html" source="REDHAT">RHSA-2003:288</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-287.html" source="REDHAT">RHSA-2003:287</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:091" source="MANDRAKE">MDKSA-2003:091</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" source="CONECTIVA">CLA-2003:747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:193" source="OVAL" sig="1">oval:org.mitre.oval:def:193</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0_beta" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.3a" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.5a" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1a" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0691" reject="1" published="2003-12-31" name="CVE-2003-0691" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not associated with any specific security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0692" published="2003-10-06" name="CVE-2003-0692" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-270.html" source="REDHAT" patch="1" adv="1">RHSA-2003:270</ref>
      <ref url="http://www.kde.org/info/security/advisory-20030916-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20030916-1.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-388" source="DEBIAN" patch="1" adv="1">DSA-388</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html" source="MISC">http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-288.html" source="REDHAT">RHSA-2003:288</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:091" source="MANDRAKE">MDKSA-2003:091</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106374551513499&amp;w=2" source="BUGTRAQ">20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" source="CONECTIVA">CLA-2003:747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:215" source="OVAL" sig="1">oval:org.mitre.oval:def:215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0_beta" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.3a" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.5a" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1a" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0693" published="2003-09-22" name="CVE-2003-0693" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/333628" source="CERT-VN" patch="1" adv="1">VU#333628</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-24.html" source="CERT">CA-2003-24</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106373247528528&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030916 OpenSSH Buffer Management Bug Advisory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13191" source="XF" adv="1">openssh-packet-bo(13191)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-280.html" source="REDHAT">RHSA-2003:280</ref>
      <ref url="http://www.openssh.com/txt/buffer.adv" source="CONFIRM">http://www.openssh.com/txt/buffer.adv</ref>
      <ref url="http://www.debian.org/security/2003/dsa-383" source="DEBIAN">DSA-383</ref>
      <ref url="http://www.debian.org/security/2003/dsa-382" source="DEBIAN">DSA-382</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000620.1-1" source="SUNALERT">1000620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381409220492&amp;w=2" source="BUGTRAQ">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381396120332&amp;w=2" source="TRUSTIX">2003-0033</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106374466212309&amp;w=2" source="BUGTRAQ">20030916 [slackware-security]  OpenSSH Security Advisory (SSA:2003-259-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106373546332230&amp;w=2" source="REDHAT">RHSA-2003:279</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010146.html" source="FULLDISC">20030916 The lowdown on SSH vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010135.html" source="FULLDISC">20030915 openssh remote exploit</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010103.html" source="FULLDISC">20030915 new ssh exploit?</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:090" source="MANDRAKE">MDKSA-2003:090</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:447" source="OVAL" sig="1">oval:org.mitre.oval:def:447</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2719" source="OVAL" sig="1">oval:org.mitre.oval:def:2719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers prev="1" num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0694" published="2003-10-06" name="CVE-2003-0694" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-25.html" source="CERT" patch="1" adv="1">CA-2003-25</ref>
      <ref url="http://www.kb.cert.org/vuls/id/784980" source="CERT-VN">VU#784980</ref>
      <ref url="http://www.sendmail.org/8.12.10.html" source="CONFIRM" patch="1">http://www.sendmail.org/8.12.10.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-284.html" source="REDHAT">RHSA-2003:284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-283.html" source="REDHAT">RHSA-2003:283</ref>
      <ref url="http://www.debian.org/security/2003/dsa-384" source="DEBIAN">DSA-384</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106398718909274&amp;w=2" source="BUGTRAQ">20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106383437615742&amp;w=2" source="BUGTRAQ">20030917 GLSA:  sendmail (200309-13)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106382859407683&amp;w=2" source="BUGTRAQ">20030917 [slackware-security]  Sendmail vulnerabilities fixed (SSA:2003-260-02)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381604923204&amp;w=2" source="BUGTRAQ">20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694]</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000742" source="CONECTIVA">CLA-2003:742</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.html" source="VULNWATCH">20030917 Zalewski Advisory - Sendmail 8.12.9 prescan bug</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.html" source="FULLDISC">20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694]</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt" source="SCO">SCOSA-2004.11</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:092" source="MANDRAKE">MDKSA-2003:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:603" source="OVAL" sig="1">oval:org.mitre.oval:def:603</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:572" source="OVAL" sig="1">oval:org.mitre.oval:def:572</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2975" source="OVAL" sig="1">oval:org.mitre.oval:def:2975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="advanced_message_server">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail">
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="8.10" />
        <vers num="8.10.1" />
        <vers num="8.10.2" />
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.11.6" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
        <vers num="8.12.0" />
        <vers num="8.12.1" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
        <vers num="8.12.9" />
        <vers num="8.8.8" />
        <vers num="8.9.0" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail_pro">
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
      <prod vendor="sendmail" name="sendmail_switch">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0f" />
        <vers num="4.0f_pk6_bl17" />
        <vers num="4.0f_pk7_bl18" />
        <vers num="4.0f_pk8_bl22" />
        <vers num="4.0g" />
        <vers num="4.0g_pk3_bl17" />
        <vers num="4.0g_pk4_bl22" />
        <vers num="5.1" />
        <vers num="5.1_pk3_bl17" />
        <vers num="5.1_pk4_bl18" />
        <vers num="5.1_pk5_bl19" />
        <vers num="5.1_pk6_bl20" />
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1a_pk4_bl21" />
        <vers num="5.1a_pk5_bl23" />
        <vers num="5.1b" />
        <vers num="5.1b_pk1_bl1" />
        <vers num="5.1b_pk2_bl22" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" edition="releng" />
        <vers num="4.0" edition="releng" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.0.4" />
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.3" />
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":x86" />
        <vers num="1.5" edition=":sh3" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" edition="beta" />
        <vers num="1.6.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_advanced_server">
        <vers num="6.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="6.0" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0695" published="2003-10-06" name="CVE-2003-0695" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-280.html" source="REDHAT" patch="1" adv="1">RHSA-2003:280</ref>
      <ref url="http://www.debian.org/security/2003/dsa-383" source="DEBIAN" patch="1" adv="1">DSA-383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106373546332230&amp;w=2" source="REDHAT" patch="1" adv="1">RHSA-2003:279</ref>
      <ref url="http://www.openssh.com/txt/buffer.adv" source="CONFIRM">http://www.openssh.com/txt/buffer.adv</ref>
      <ref url="http://www.debian.org/security/2003/dsa-382" source="DEBIAN">DSA-382</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=106375582924840" source="MISC">http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=106375582924840</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106382542403716&amp;w=2" source="BUGTRAQ">20030917 [slackware-security]  OpenSSH updated again (SSA:2003-260-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381409220492&amp;w=2" source="BUGTRAQ">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381396120332&amp;w=2" source="TRUSTIX">2003-0033</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000741" source="CONECTIVA">CLA-2003:741</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:090" source="MANDRAKE">MDKSA-2003:090</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:452" source="OVAL" sig="1">oval:org.mitre.oval:def:452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers prev="1" num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0696" published="2004-01-20" name="CVE-2003-0696" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8738" source="BID" patch="1" adv="1">8738</ref>
      <ref url="https://techsupport.services.ibm.com/server/pseries.subscriptionSvcs?mode=7&amp;heading=AIX51&amp;topic=SECURITY&amp;month=200310&amp;label=getipnodebyname%28%29+API+does+not+close+sockets.&amp;date=20031001&amp;bulletin=datafile150755&amp;embed=true" source="CONFIRM">https://techsupport.services.ibm.com/server/pseries.subscriptionSvcs?mode=7&amp;heading=AIX51&amp;topic=SECURITY&amp;month=200310&amp;label=getipnodebyname%28%29+API+does+not+close+sockets.&amp;date=20031001&amp;bulletin=datafile150755&amp;embed=true</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13328" source="XF" adv="1">aix-sendmail-getipnodebyname-dos(13328)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0697" published="2003-10-06" name="CVE-2003-0697" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY45344&amp;apar=only" source="AIXAPAR" adv="1">IY45344</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1605.1" source="CONFIRM">http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1605.1</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY46256&amp;apar=only" source="AIXAPAR">IY46256</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY45250&amp;apar=only" source="AIXAPAR">IY45250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0698" reject="1" published="2003-12-31" name="CVE-2003-0698" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0743.  Reason: This candidate is a duplicate of CVE-2003-0743.  Notes: All CVE users should reference CVE-2003-0743 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0699" published="2003-08-27" name="CVE-2003-0699" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT" patch="1" adv="1">RHSA-2003:198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:387" source="OVAL" sig="1">oval:org.mitre.oval:def:387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0700" published="2004-02-17" name="CVE-2003-0700" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-044.html" source="REDHAT" patch="1" adv="1">RHSA-2004:044</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:401" source="OVAL" sig="1">oval:org.mitre.oval:def:401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="kernel">
        <vers prev="1" num="2.4.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0701" published="2003-08-27" name="CVE-2003-0701" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/334928" source="CERT-VN">VU#334928</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS" patch="1" adv="1">MS03-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106148101210479&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030820 [SNS Advisory No.68] Internet Explorer Object Type Buffer Overflow in Double-Byte Character Set Environment</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12970" source="XF">ie-dbcs-object-bo(12970)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows_server_2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0702" published="2003-10-20" name="CVE-2003-0702" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server (IIS) via a certain URL through SSL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13088" source="XF" patch="1" adv="1">realsecure-isapi-dos(13088)</ref>
      <ref url="http://www.enteredge.com/research/CAN-2003-0702.asp" source="MISC">http://www.enteredge.com/research/CAN-2003-0702.asp</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106278164225389&amp;w=2" source="BUGTRAQ">20030905 ISS Server Sensor Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="realsecure_server_sensor">
        <vers num="7.0" edition="xpu20.16" />
        <vers num="7.0" edition="xpu20.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0703" published="2003-09-17" name="CVE-2003-0703" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">KisMAC before 0.05d trusts user-supplied variables to load arbitrary kernels or kernel modules, which allows local users to gain privileges via the $DRIVER_KEXT environment variable as used in (1) viha_driver.sh, (2) macjack_load.sh, or (3) airojack_load.sh, or (4) via "similar techniques" using exchangeKernel.sh.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13007" source="XF" patch="1" adv="1">kismac-driverkext-load-modules(13007)</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a082203-1.txt" source="ATSTAKE" patch="1" adv="1">A082203-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13008" source="XF">kismac-exchangekernel-kernel-overwrite(13008)</ref>
      <ref url="http://www.securityfocus.com/bid/8497" source="BID" adv="1">8497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kismac" name="kismac">
        <vers num="0.05d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0704" published="2003-09-17" name="CVE-2003-0704" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">KisMAC before 0.05d trusts user-supplied variables when chown'ing files or directories, which allows local users to gain privileges via the $DRIVER_KEXT environment variable in (1) viha_driver.sh, (2) macjack_load.sh, (3) airojack_load.sh, (4) setuid_enable.sh, (5) setuid_disable.sh, and using a "similar technique" for (6) viha_prep.sh and (7) viha_unprep.sh.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13009" source="XF" patch="1" adv="1">kismac-setuid-modify-ownership(13009)</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a082203-1.txt" source="ATSTAKE" patch="1" adv="1">A082203-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13010" source="XF">kismac-viha-gain-privileges</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13006" source="XF">kismac-driverkext-modify-ownership</ref>
      <ref url="http://www.securityfocus.com/bid/8497" source="BID" adv="1">8497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kismac" name="kismac">
        <vers num="0.05d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0705" published="2003-09-17" name="CVE-2003-0705" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-378" source="DEBIAN" patch="1">DSA-378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicolas_boullis" name="mah-jong">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0706" published="2003-09-17" name="CVE-2003-0706" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-378" source="DEBIAN" patch="1">DSA-378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicolas_boullis" name="mah-jong">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0707" published="2003-10-20" name="CVE-2003-0707" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-375" source="DEBIAN" patch="1" adv="1">DSA-375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomi_manninen" name="linuxnode">
        <vers prev="1" num="0.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0708" published="2003-10-20" name="CVE-2003-0708" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-375" source="DEBIAN" patch="1" adv="1">DSA-375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomi_manninen" name="linuxnode">
        <vers prev="1" num="0.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0709" published="2003-10-20" name="CVE-2003-0709" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zone-h.org/en/advisories/read/id=2925/" source="MISC" patch="1" adv="1">http://www.zone-h.org/en/advisories/read/id=2925/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whois" name="whois">
        <vers num="4.5.7" />
        <vers num="4.6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0711" published="2003-11-17" name="CVE-2003-0711" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/467036" source="CERT-VN" patch="1" adv="1">VU#467036</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8828" source="BID" patch="1" adv="1">8828</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-044.asp" source="MS" patch="1" adv="1">MS03-044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106631908105696&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031016 Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)</ref>
      <ref url="http://www.ngssoftware.com/advisories/ms-pchealth.txt" source="MISC">http://www.ngssoftware.com/advisories/ms-pchealth.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106632194809632&amp;w=2" source="NTBUGTRAQ">20031016 Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4706" source="OVAL" sig="1">oval:org.mitre.oval:def:4706</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3889" source="OVAL" sig="1">oval:org.mitre.oval:def:3889</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3685" source="OVAL" sig="1">oval:org.mitre.oval:def:3685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:217" source="OVAL" sig="1">oval:org.mitre.oval:def:217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0712" published="2003-11-17" name="CVE-2003-0712" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/435444" source="CERT-VN" patch="1" adv="1">VU#435444</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8832" source="BID" patch="1" adv="1">8832</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-047.asp" source="MS" patch="1" adv="1">MS03-047</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106631918405915&amp;w=2" source="BUGTRAQ" adv="1">20031016 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="5.5" edition="sp3" />
        <vers num="5.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0714" published="2003-11-17" name="CVE-2003-0714" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/422156" source="CERT-VN" patch="1" adv="1">VU#422156</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8838" source="BID" patch="1" adv="1">8838</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-046.asp" source="MS" patch="1" adv="1">MS03-046</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106682909006586&amp;w=2" source="BUGTRAQ">20031022 MS03-046 Microsoft Exchange 2000 Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="5.5" edition="sp3" />
        <vers num="5.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0715" published="2003-09-17" name="CVE-2003-0715" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/483492" source="CERT-VN">VU#483492</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-23.html" source="CERT">CA-2003-23</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-039.asp" source="MS" patch="1" adv="1">MS03-039</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106322856608909&amp;w=2" source="BUGTRAQ">20030910 EEYE: Microsoft RPC Heap Corruption Vulnerability - Part II</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4224" source="OVAL" sig="1">oval:org.mitre.oval:def:4224</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:264" source="OVAL" sig="1">oval:org.mitre.oval:def:264</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:20" source="OVAL" sig="1">oval:org.mitre.oval:def:20</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1813" source="OVAL" sig="1">oval:org.mitre.oval:def:1813</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1202" source="OVAL" sig="1">oval:org.mitre.oval:def:1202</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0717" published="2003-11-17" name="CVE-2003-0717" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/575892" source="CERT-VN" patch="1" adv="1">VU#575892</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-27.html" source="CERT">CA-2003-27</ref>
      <ref url="http://www.securityfocus.com/bid/8826" source="BID" patch="1" adv="1">8826</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-043.asp" source="MS" patch="1" adv="1">MS03-043</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106632188709562&amp;w=2" source="BUGTRAQ">20031016 MS03-043 Popup Messenger Servce buffer-overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106666713812158&amp;w=2" source="BUGTRAQ">20031018 Proof of concept for Windows Messenger Service overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:268" source="OVAL" sig="1">oval:org.mitre.oval:def:268</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:213" source="OVAL" sig="1">oval:org.mitre.oval:def:213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0718" published="2004-11-03" name="CVE-2003-0718" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17656" source="XF" patch="1" adv="1">iis-ms04030-patch(17656)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17645" source="XF" patch="1" adv="1">iis-webdav-xml-attribute-dos(17645)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-030.asp" source="MS" patch="1" adv="1">MS04-030</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109762641822064&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041012 Microsoft IIS 5.x/6.0 WebDAV (XML parser) attribute blowup DoS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4767" source="OVAL" sig="1">oval:org.mitre.oval:def:4767</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1427" source="OVAL" sig="1">oval:org.mitre.oval:def:1427</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1330" source="OVAL" sig="1">oval:org.mitre.oval:def:1330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0719" published="2004-06-01" name="CVE-2003-0719" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/586540" source="CERT-VN" patch="1" adv="1">VU#586540</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/168" source="ISS" patch="1" adv="1">20040413 Microsoft SSL Library Remote Compromise Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/361836" source="BUGTRAQ" patch="1" adv="1">20040430 A technical description of the SSL PCT vulnerability (CVE-2003-0719)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:951" source="OVAL" sig="1">oval:org.mitre.oval:def:951</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:903" source="OVAL" sig="1">oval:org.mitre.oval:def:903</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:889" source="OVAL" sig="1">oval:org.mitre.oval:def:889</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1093" source="OVAL" sig="1">oval:org.mitre.oval:def:1093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0720" published="2003-09-17" name="CVE-2003-0720" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-273.html" source="REDHAT" patch="1" adv="1">RHSA-2003:273</ref>
      <ref url="http://www.idefense.com/advisory/09.10.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/09.10.03.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-274.html" source="REDHAT">RHSA-2003:274</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0099.html" source="VULNWATCH">20030910 iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106329356702508&amp;w=2" source="BUGTRAQ">20030911 [slackware-security]  security issues in pine (SSA:2003-253-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106322571805153&amp;w=2" source="BUGTRAQ">20030910 iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:499" source="OVAL" sig="1">oval:org.mitre.oval:def:499</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers num="3.98" />
        <vers num="4.0.2" />
        <vers num="4.0.4" />
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.30" />
        <vers num="4.33" />
        <vers num="4.44" />
        <vers num="4.50" />
        <vers num="4.52" />
        <vers num="4.53" />
        <vers num="4.56" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0721" published="2003-09-17" name="CVE-2003-0721" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-273.html" source="REDHAT" patch="1" adv="1">RHSA-2003:273</ref>
      <ref url="http://www.idefense.com/advisory/09.10.03.txt" source="IDEFENSE" patch="1" adv="1">20030910 Two Exploitable Overflows in PINE</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-274.html" source="REDHAT">RHSA-2003:274</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009850.html" source="FULLDISC">20030911 Pine: .procmailrc rule against integer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106367213400313&amp;w=2" source="BUGTRAQ">20030915 remote Pine &lt;= 4.56 exploit fully automatic</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106329356702508&amp;w=2" source="BUGTRAQ">20030911 [slackware-security]  security issues in pine (SSA:2003-253-01)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:503" source="OVAL" sig="1">oval:org.mitre.oval:def:503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers num="3.98" />
        <vers num="4.0.2" />
        <vers num="4.0.4" />
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.30" />
        <vers num="4.33" />
        <vers num="4.44" />
        <vers num="4.50" />
        <vers num="4.52" />
        <vers num="4.53" />
        <vers num="4.56" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0722" published="2003-09-22" name="CVE-2003-0722" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/41870" source="CERT-VN">VU#41870</ref>
      <ref url="http://www.securityfocus.com/bid/8615" source="BID">8615</ref>
      <ref url="http://www.idefense.com/advisory/09.16.03.txt" source="MISC">http://www.idefense.com/advisory/09.16.03.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-148.shtml" source="CIAC">N-148</ref>
      <ref url="http://secunia.com/advisories/9742" source="SECUNIA">9742</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0115.html" source="VULNWATCH">20030918 Solaris SADMIND Exploitation</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56740-1&amp;searchclause=security" source="SUNALERT">56740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106391959014331&amp;w=2" source="BUGTRAQ">20030918 Solaris SADMIND Exploitation</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1273" source="OVAL" sig="1">oval:org.mitre.oval:def:1273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0723" published="2003-10-20" name="CVE-2003-0723" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:087" source="MANDRAKE">MDKSA-2003:087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gkrellm" name="gkrellm">
        <vers num="2.1.13" />
        <vers num="2.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0724" published="2003-10-20" name="CVE-2003-0724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8492" source="BID" patch="1" adv="1">8492</ref>
      <ref url="http://www.securityfocus.com/advisories/5736" source="HP" adv="1">SSRT3588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="tru64">
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1a_pk4_bl21" />
        <vers num="5.1a_pk5_bl23" />
        <vers num="5.1b_pk2_bl22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0725" published="2003-10-20" name="CVE-2003-0725" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/934932" source="CERT-VN" adv="1">VU#934932</ref>
      <ref url="http://www.securityfocus.com/bid/8476" source="BID" patch="1" adv="1">8476</ref>
      <ref url="http://www.service.real.com/help/faq/security/rootexploit082203.html" source="CONFIRM">http://www.service.real.com/help/faq/security/rootexploit082203.html</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html" source="MISC">http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0087.html" source="VULNWATCH" adv="1">20030825 New Bug in RealServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_universal_server">
        <vers num="8.0.1" />
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.2.794" />
      </prod>
      <prod vendor="realnetworks" name="realserver">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0_beta" />
        <vers num="g2_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0726" published="2003-10-20" name="CVE-2003-0726" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8453" source="BID" patch="1" adv="1">8453</ref>
      <ref url="http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html" source="MISC" patch="1" adv="1">http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13028" source="XF">realone-smil-execute-code(13028)</ref>
      <ref url="http://www.service.real.com/help/faq/security/securityupdate_august2003.html" source="CONFIRM">http://www.service.real.com/help/faq/security/securityupdate_august2003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/335293" source="BUGTRAQ" adv="1">20030827 RealOne Player Allows Cross Zone and Domain Access</ref>
      <ref url="http://securitytracker.com/id?1007532" source="SECTRACK">1007532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_desktop_manager">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="2.0" />
        <vers num="6.0.10.505" edition="gold" />
        <vers num="6.0.11.818" />
        <vers num="6.0.11.830" />
        <vers num="6.0.11.841" />
        <vers num="6.0.11.853" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0727" published="2003-10-20" name="CVE-2003-0727" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003Alert58.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003Alert58.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0728" published="2003-10-20" name="CVE-2003-0728" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252836330987&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030901 GLSA:  horde (200309-02)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106081310531567&amp;w=2" source="BUGTRAQ" adv="1">20030813 PCL-0001: Remote Vulnerability in HORDE MTA &lt; 2.2.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde">
        <vers prev="1" num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0729" published="2003-10-20" name="CVE-2003-0729" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/windowsntfocus/5RP0M1PAUM.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5RP0M1PAUM.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252411425545&amp;w=2" source="BUGTRAQ" adv="1">20030901 Security Vulnerability in Tellurian TftpdNT (Long Filename)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0091.html" source="VULNWATCH" adv="1">20030901 Security Vulnerability in Tellurian TftpdNT (Long Filename)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tellurian" name="tftpdnt">
        <vers num="1.8" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0730" published="2003-10-20" name="CVE-2003-0730" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8514" source="BID" patch="1" adv="1">8514</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-286.html" source="REDHAT" patch="1" adv="1">RHSA-2003:286</ref>
      <ref url="http://www.debian.org/security/2003/dsa-380" source="DEBIAN" patch="1" adv="1">DSA-380</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106229335312429&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030830 Multiple integer overflows in XFree86 (local/remote)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0589" source="VUPEN">ADV-2007-0589</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-289.html" source="REDHAT">RHSA-2003:289</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-288.html" source="REDHAT">RHSA-2003:288</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031101-01-U.asc" source="SGI">20031101-01-U</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-015.txt.asc" source="NETBSD">NetBSD-SA2003-015</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-287.html" source="REDHAT">RHSA-2003:287</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:089" source="MANDRAKE">MDKSA-2003:089</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1" source="SUNALERT">102803</ref>
      <ref url="http://secunia.com/advisories/24247" source="SECUNIA">24247</ref>
      <ref url="http://secunia.com/advisories/24168" source="SECUNIA">24168</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.2.1" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" />
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0731" published="2003-10-20" name="CVE-2003-0731" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml" source="CISCO" patch="1" adv="1">20030813 CiscoWorks Application Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/333028" source="BUGTRAQ" adv="1">20030813 Portcullis Security Advisory: CiscoWorks 2000 Privilege Escalation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="cisco" name="resource_manager">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="cisco" name="resource_manager_essentials">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_cd1">
        <vers num="1st" />
        <vers num="2nd" />
        <vers num="3rd" />
        <vers num="4th" />
        <vers num="5th" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0732" published="2003-10-20" name="CVE-2003-0732" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml" source="CISCO" patch="1" adv="1">20030813 CiscoWorks Application Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/333028" source="BUGTRAQ" adv="1">20030813 Portcullis Security Advisory: CiscoWorks 2000 Privilege Escalation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="cisco" name="resource_manager">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="cisco" name="resource_manager_essentials">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_cd1">
        <vers num="1st" />
        <vers num="2nd" />
        <vers num="3rd" />
        <vers num="4th" />
        <vers num="5th" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0733" published="2003-10-20" name="CVE-2003-0733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other vulnerabilities in the WebLogic Server console application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8357" source="BID" patch="1" adv="1">8357</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="liquid_data">
        <vers num="1.1" />
      </prod>
      <prod vendor="bea" name="weblogic_integration">
        <vers num="2.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers num="5.1" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0734" published="2003-10-20" name="CVE-2003-0734" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:088" source="MANDRAKE">MDKSA-2003:088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="padl_software" name="pam_ldap">
        <vers prev="1" num="162" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0735" published="2003-10-20" name="CVE-2003-0735" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/925166" source="CERT-VN">VU#925166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252188522715&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030902 GLSA:  phpwebsite (200309-03)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106062021711496&amp;w=2" source="BUGTRAQ" adv="1">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers prev="1" num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0736" published="2003-10-20" name="CVE-2003-0736" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/664422" source="CERT-VN">VU#664422</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252188522715&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030902 GLSA:  phpwebsite (200309-03)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106062021711496&amp;w=2" source="BUGTRAQ" adv="1">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers prev="1" num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0737" published="2003-10-20" name="CVE-2003-0737" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252188522715&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030902 GLSA:  phpwebsite (200309-03)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106062021711496&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers prev="1" num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0738" published="2003-10-20" name="CVE-2003-0738" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252188522715&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030902 GLSA:  phpwebsite (200309-03)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106062021711496&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers prev="1" num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0739" published="2003-10-20" name="CVE-2003-0739" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1106" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1106</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106029217115023&amp;w=2" source="BUGTRAQ" adv="1">20030807 VMware Workstation 4.0.1 (for Linux systems) vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="4.0.1_build_5289" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0740" published="2003-10-20" name="CVE-2003-0740" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106260760211958&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030903 Stunnel-3.x Daemon Hijacking</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-297.html" source="REDHAT">RHSA-2003:297</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:108" source="MANDRAKE">MDKSA-2003:108</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000736" source="CONECTIVA">CLA-2003:736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stunnel" name="stunnel">
        <vers num="3.10" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="3.14" />
        <vers num="3.15" />
        <vers num="3.16" />
        <vers num="3.17" />
        <vers num="3.18" />
        <vers num="3.19" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.21a" />
        <vers num="3.21b" />
        <vers num="3.21c" />
        <vers num="3.22" />
        <vers num="3.24" />
        <vers num="3.3" />
        <vers num="3.4a" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0742" published="2003-10-06" name="CVE-2003-0742" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0743" published="2003-10-20" name="CVE-2003-0743" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-376" source="DEBIAN" patch="1" adv="1">DSA-376</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106252015820395&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030901 exim remote heap overflow, probably not exploitable</ref>
      <ref url="http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.html" source="MLIST">[Exim] 20030815 Minor security bug</ref>
      <ref url="http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.html" source="MLIST">[Exim] 20030814 Minor security bug</ref>
      <ref url="http://www.exim.org/pipermail/exim-announce/2003q3/000094.html" source="CONFIRM">http://www.exim.org/pipermail/exim-announce/2003q3/000094.html</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=106264740820334&amp;w=2" source="VULN-DEV">20030903 Re: exim remote heap overflow, probably not exploitable</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000735" source="CONECTIVA">CLA-2003:735</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers num="3.0" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="3.14" />
        <vers num="3.15" />
        <vers num="3.16" />
        <vers num="3.17" />
        <vers num="3.18" />
        <vers num="3.19" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.30" />
        <vers num="3.31" />
        <vers num="3.32" />
        <vers num="3.33" />
        <vers num="3.34" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="4.10" />
        <vers num="4.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0744" published="2003-10-20" name="CVE-2003-0744" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8541" source="BID">8541</ref>
      <ref url="http://www.osvdb.org/6452" source="OSVDB">6452</ref>
      <ref url="http://secunia.com/advisories/9678" source="SECUNIA">9678</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106270038210736&amp;w=2" source="BUGTRAQ" adv="1">20030904 leafnode 1.9.3 - 1.9.41 security announcement SA-2003-01</ref>
      <ref url="http://leafnode.sourceforge.net/leafnode-SA-2003-01.txt" source="CONFIRM">http://leafnode.sourceforge.net/leafnode-SA-2003-01.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/" source="VULNWATCH" adv="1">20030903 leafnode 1.9.3 - 1.9.41 security announcement SA-2003-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leafnode" name="leafnode">
        <vers num="1.9.19" />
        <vers num="1.9.20" />
        <vers num="1.9.21" />
        <vers num="1.9.22" />
        <vers num="1.9.23" />
        <vers num="1.9.24" />
        <vers num="1.9.25" />
        <vers num="1.9.26" />
        <vers num="1.9.27" />
        <vers num="1.9.29" />
        <vers num="1.9.30" />
        <vers num="1.9.31" />
        <vers num="1.9.35" />
        <vers num="1.9.36" />
        <vers num="1.9.37" />
        <vers num="1.9.38" />
        <vers num="1.9.39" />
        <vers num="1.9.40" />
        <vers num="1.9.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0745" published="2003-10-20" name="CVE-2003-0745" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0340.html" source="BUGTRAQ" patch="1" adv="1">20030825 SNMPc v5 and v6 remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="castle_rock_computing" name="snmpc">
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.5" />
        <vers num="6.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0746" published="2003-10-20" name="CVE-2003-0746" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerabilities CVE-2003-0352 or CVE-2003-0605, such as the Blaster/MSblast/LovSAN worm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/377804" source="CERT-VN" adv="1">VU#377804</ref>
      <ref url="http://www.secunia.com/advisories/9482" source="SECUNIA" adv="1">9482</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q3/0042.html" source="HP">HPSBUX0308-274</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030902-01-P" source="SGI">20030902-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0747" published="2003-10-20" name="CVE-2003-0747" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~language, (4) ~theme, or (5) ~template, which leaks the information in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13063" source="XF" adv="1">its-wgatedll-information-disclosure(13063)</ref>
      <ref url="http://www.securityfocus.com/bid/8515" source="BID" adv="1">8515</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" source="BUGTRAQ" adv="1">20030830 SAP Internet Transaction Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="internet_transaction_server">
        <vers num="4620.2.0.323011" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0748" published="2003-10-20" name="CVE-2003-0748" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13066" source="XF" adv="1">its-wgatedll-directory-traversal(13066)</ref>
      <ref url="http://www.securityfocus.com/bid/8516" source="BID" adv="1">8516</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" source="BUGTRAQ" adv="1">20030830 SAP Internet Transaction Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="internet_transaction_server">
        <vers num="4620.2.0.323011" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0749" published="2003-10-20" name="CVE-2003-0749" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8517" source="BID" adv="1">8517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" source="BUGTRAQ" adv="1">20030830 SAP Internet Transaction Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="internet_transaction_server">
        <vers num="4620.2.0.323011" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0750" published="2003-10-20" name="CVE-2003-0750" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0089.html" source="VULNWATCH">20030826 [PHP] PY-Membres 4.2 : Admin Access, SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py-membres" name="py-membres">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0751" published="2003-10-20" name="CVE-2003-0751" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0089.html" source="VULNWATCH" adv="1">20030826 [PHP] PY-Membres 4.2 : Admin Access, SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py-membres" name="py-membres">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0752" published="2003-10-20" name="CVE-2003-0752" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0090.html" source="VULNWATCH" adv="1">20030826 [PHP] AttilaPHP 3.0 : User/Admin Access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="attila-php.net" name="attilaphp">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0753" published="2003-10-20" name="CVE-2003-0753" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html" source="BUGTRAQ" adv="1">20030824 newsPHP file inclusion &amp; bad login validation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsphp" name="newsphp">
        <vers prev="1" num="216" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0754" published="2003-10-20" name="CVE-2003-0754" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html" source="BUGTRAQ" adv="1">20030824 newsPHP file inclusion &amp; bad login validation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsphp" name="newsphp">
        <vers prev="1" num="216" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0755" published="2003-10-20" name="CVE-2003-0755" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2003-q3/0101.html" source="VULN-DEV" adv="1">20030826 gtkftpd[v1.0.4(and below)]: remote root buffer overflow exploit.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtkftpd" name="gtkftp">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0756" published="2003-10-20" name="CVE-2003-0756" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0011.html" source="BUGTRAQ">20030831 Directory Traversal in SITEBUILDER - v1.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitebuilder" name="sitebuilder">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0757" published="2003-10-20" name="CVE-2003-0757" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0018.html" source="BUGTRAQ" adv="1">20030902 IRM 007: The IP addresses of Check Point Firewall-1 internal interfaces may be enumerated using SecuRemote</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0758" published="2003-10-06" name="CVE-2003-0758" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8552" source="BID" patch="1" adv="1">8552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13218" source="XF">ibm-db2-db2dart-bo(13218)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-154.shtml" source="CIAC">N-154</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106389919618721&amp;w=2" source="BUGTRAQ">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0114.html" source="VULNWATCH">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0759" published="2003-10-06" name="CVE-2003-0759" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8553" source="BID" patch="1" adv="1">8553</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-154.shtml" source="CIAC">N-154</ref>
      <ref url="http://www-3.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/aparlib.d2w/display_apar_details?aparno=IY47653" source="AIXAPAR">IY47653</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106389919618721&amp;w=2" source="BUGTRAQ">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0114.html" source="VULNWATCH">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0760" published="2003-09-17" name="CVE-2003-0760" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/windowsntfocus/5RP0N15AUC.html" source="MISC" patch="1">http://www.securiteam.com/windowsntfocus/5RP0N15AUC.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13012" source="XF" adv="1">blubster-port701-dos(13012)</ref>
      <ref url="http://www.securityfocus.com/bid/8482" source="BID" adv="1">8482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="optisoft" name="blubster">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0761" published="2003-09-17" name="CVE-2003-0761" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before August 15, 2003, allows remote attackers to execute arbitrary code via certain (1) MESSAGE or (2) INFO requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a090403-1.txt" source="ATSTAKE" adv="1">A090403-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="1.2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0762" published="2003-09-17" name="CVE-2003-0762" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0096.html" source="VULNWATCH" adv="1">20030905 [SCAN Associates Sdn Bhd Security Advisory] Foxweb 2.5 bufferoverflow in CGI and ISAPI extension</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxweb" name="foxweb">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0763" published="2003-09-17" name="CVE-2003-0763" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106312344631197&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030909 Escapade Scripting Engine XSS Vulnerability and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squished_mosquito" name="escapade">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0764" published="2003-09-17" name="CVE-2003-0764" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Escapade Scripting Engine (ESP) allows remote attackers to obtain sensitive path information via a malformed request, which leaks the information in an error message, as demonstrated using the PAGE parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106312344631197&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030909 Escapade Scripting Engine XSS Vulnerability and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squished_mosquito" name="escapade">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0765" published="2003-09-17" name="CVE-2003-0765" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106305643432112&amp;w=2" source="BUGTRAQ" adv="1">20030908 Winamp 2.91 lets code execution through MIDI files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.81" />
        <vers num="2.91" />
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0766" published="2003-09-17" name="CVE-2003-0766" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER copmmand, or (3) a long response to a PASS command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106305502230604&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030908 Multiple Heap Overflows in FTP Desktop</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftp_desktop" name="ftp_desktop">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0767" published="2003-09-17" name="CVE-2003-0767" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client request with a large length value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106304902323758&amp;w=2" source="BUGTRAQ">20030908 Rogerwilco: server's buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamespy" name="roger_wilco_dedicated_server">
        <vers num="0.26" />
        <vers num="0.27" />
        <vers num="0.28" />
        <vers num="0.29" />
        <vers num="0.30a" />
      </prod>
      <prod vendor="gamespy" name="roger_wilco_graphical_server">
        <vers num="1.4.1.1" />
        <vers num="1.4.1.2" />
        <vers num="1.4.1.3" />
        <vers num="1.4.1.4" />
        <vers num="1.4.1.5" />
        <vers num="1.4.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0768" published="2003-09-22" name="CVE-2003-0768" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106304326916062&amp;w=2" source="BUGTRAQ" adv="1">20030908 Advisory: Incorrect Handling of XSS Protection in ASP.Net</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0769" published="2003-09-22" name="CVE-2003-0769" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2003a_build3777" />
        <vers num="2003a_build3799" />
        <vers num="2003a_build3800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0770" published="2003-09-22" name="CVE-2003-0770" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/317234" source="BUGTRAQ" patch="1" adv="1">20030401 IkonBoard v3.1.1: arbitrary command execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/336598" source="BUGTRAQ">20030908 IkonBoard 3.1.2a arbitrary command execution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381136115972&amp;w=2" source="BUGTRAQ">20030917 Exploit: IkonBoard 3.1.1/3.1.2a arbitrary command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikonboard.com" name="ikonboard">
        <vers num="3.1.1" />
        <vers num="3.1.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0771" published="2003-09-22" name="CVE-2003-0771" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106304236914921&amp;w=2" source="BUGTRAQ" adv="1">20030907 Apache::Gallery local webserver compromise, privilege escalation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache_gallery" name="apache_gallery">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0772" published="2003-09-22" name="CVE-2003-0772" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/792284" source="CERT-VN">VU#792284</ref>
      <ref url="http://www.kb.cert.org/vuls/id/219140" source="CERT-VN">VU#219140</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13119" source="XF">wsftp-ftp-command-bo(13119)</ref>
      <ref url="http://www.securityfocus.com/bid/8542" source="BID" adv="1">8542</ref>
      <ref url="http://secunia.com/advisories/9671" source="SECUNIA">9671</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106288825902868&amp;w=2" source="BUGTRAQ">20030906 Remote and Local Vulnerabilities In WS_FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="3.4" />
        <vers num="4.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0773" published="2003-09-22" name="CVE-2003-0773" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8595" source="BID" patch="1" adv="1">8595</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-278.html" source="REDHAT" patch="1" adv="1">RHSA-2003:278</ref>
      <ref url="http://www.debian.org/security/2003/dsa-379" source="DEBIAN" patch="1" adv="1">DSA-379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-285.html" source="REDHAT">RHSA-2003:285</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_046_sane.html" source="SUSE">SuSE-SA:2003:046</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" source="SCO">CSSA-2004-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/8593" source="BID">8593</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" source="MANDRAKE">MDKSA-2003:099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sane" name="sane">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.7_beta1" />
        <vers num="1.0.7_beta2" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="sane" name="sane-backend">
        <vers num="1.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0774" published="2003-09-22" name="CVE-2003-0774" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-278.html" source="REDHAT" patch="1" adv="1">RHSA-2003:278</ref>
      <ref url="http://www.debian.org/security/2003/dsa-379" source="DEBIAN" patch="1" adv="1">DSA-379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-285.html" source="REDHAT">RHSA-2003:285</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_046_sane.html" source="SUSE">SuSE-SA:2003:046</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" source="SCO">CSSA-2004-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/8593" source="BID">8593</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" source="MANDRAKE">MDKSA-2003:099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sane" name="sane">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.7_beta1" />
        <vers num="1.0.7_beta2" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="sane" name="sane-backend">
        <vers num="1.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0775" published="2003-09-22" name="CVE-2003-0775" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8600" source="BID" patch="1" adv="1">8600</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-278.html" source="REDHAT" patch="1" adv="1">RHSA-2003:278</ref>
      <ref url="http://www.debian.org/security/2003/dsa-379" source="DEBIAN" patch="1" adv="1">DSA-379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-285.html" source="REDHAT">RHSA-2003:285</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_046_sane.html" source="SUSE">SuSE-SA:2003:046</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" source="SCO">CSSA-2004-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/8593" source="BID">8593</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" source="MANDRAKE">MDKSA-2003:099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sane" name="sane">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.7_beta1" />
        <vers num="1.0.7_beta2" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="sane" name="sane-backend">
        <vers num="1.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0776" published="2003-09-22" name="CVE-2003-0776" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-278.html" source="REDHAT" patch="1" adv="1">RHSA-2003:278</ref>
      <ref url="http://www.debian.org/security/2003/dsa-379" source="DEBIAN" patch="1" adv="1">DSA-379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-285.html" source="REDHAT">RHSA-2003:285</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_046_sane.html" source="SUSE">SuSE-SA:2003:046</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" source="SCO">CSSA-2004-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/8593" source="BID">8593</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" source="MANDRAKE">MDKSA-2003:099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sane" name="sane">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.7_beta1" />
        <vers num="1.0.7_beta2" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="sane" name="sane-backend">
        <vers num="1.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0777" published="2003-09-22" name="CVE-2003-0777" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-278.html" source="REDHAT" patch="1" adv="1">RHSA-2003:278</ref>
      <ref url="http://www.debian.org/security/2003/dsa-379" source="DEBIAN" patch="1" adv="1">DSA-379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-285.html" source="REDHAT">RHSA-2003:285</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_046_sane.html" source="SUSE">SuSE-SA:2003:046</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" source="SCO">CSSA-2004-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/8597" source="BID">8597</ref>
      <ref url="http://www.securityfocus.com/bid/8593" source="BID">8593</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" source="MANDRAKE">MDKSA-2003:099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sane" name="sane">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.7_beta1" />
        <vers num="1.0.7_beta2" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="sane" name="sane-backend">
        <vers num="1.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0778" published="2003-09-22" name="CVE-2003-0778" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-278.html" source="REDHAT" patch="1" adv="1">RHSA-2003:278</ref>
      <ref url="http://www.debian.org/security/2003/dsa-379" source="DEBIAN" patch="1" adv="1">DSA-379</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-285.html" source="REDHAT">RHSA-2003:285</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_046_sane.html" source="SUSE">SuSE-SA:2003:046</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt" source="SCO">CSSA-2004-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/8596" source="BID">8596</ref>
      <ref url="http://www.securityfocus.com/bid/8593" source="BID">8593</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099" source="MANDRAKE">MDKSA-2003:099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sane" name="sane">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.7_beta1" />
        <vers num="1.0.7_beta2" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="sane" name="sane-backend">
        <vers num="1.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0779" published="2003-09-22" name="CVE-2003-0779" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a091103-1.txt" source="ATSTAKE" adv="1">A091103-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.1.9.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0780" published="2003-09-22" name="CVE-2003-0780" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/516492" source="CERT-VN">VU#516492</ref>
      <ref url="http://www.securityfocus.com/archive/1/337012" source="BUGTRAQ" patch="1" adv="1">20030910 Buffer overflow in MySQL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-281.html" source="REDHAT" patch="1" adv="1">RHSA-2003:281</ref>
      <ref url="http://www.debian.org/security/2003/dsa-381" source="DEBIAN" patch="1" adv="1">DSA-381</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-282.html" source="REDHAT">RHSA-2003:282</ref>
      <ref url="http://secunia.com/advisories/9709" source="SECUNIA">9709</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106381424420775&amp;w=2" source="TRUSTIX">2003-0034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106364207129993&amp;w=2" source="BUGTRAQ">20030913 exploit for mysql -- [get_salt_from_password] problem</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009819.html" source="FULLDISC">20030910 Buffer overflow in MySQL</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" source="CONECTIVA">CLA-2003:743</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:094" source="MANDRAKE">MDKSA-2003:094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23" />
        <vers num="3.23.10" />
        <vers num="3.23.2" />
        <vers num="3.23.22" />
        <vers num="3.23.23" />
        <vers num="3.23.24" />
        <vers num="3.23.25" />
        <vers num="3.23.26" />
        <vers num="3.23.27" />
        <vers num="3.23.28" edition="gamma" />
        <vers num="3.23.29" />
        <vers num="3.23.3" />
        <vers num="3.23.30" />
        <vers num="3.23.31" />
        <vers num="3.23.32" />
        <vers num="3.23.33" />
        <vers num="3.23.34" />
        <vers num="3.23.36" />
        <vers num="3.23.37" />
        <vers num="3.23.38" />
        <vers num="3.23.39" />
        <vers num="3.23.4" />
        <vers num="3.23.40" />
        <vers num="3.23.41" />
        <vers num="3.23.42" />
        <vers num="3.23.43" />
        <vers num="3.23.44" />
        <vers num="3.23.45" />
        <vers num="3.23.46" />
        <vers num="3.23.47" />
        <vers num="3.23.48" />
        <vers num="3.23.49" />
        <vers num="3.23.5" />
        <vers num="3.23.50" />
        <vers num="3.23.51" />
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.53a" />
        <vers num="3.23.54" />
        <vers num="3.23.54a" />
        <vers num="3.23.55" />
        <vers num="3.23.56" />
        <vers num="3.23.8" />
        <vers num="3.23.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0781" published="2004-05-04" name="CVE-2003-0781" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-467" source="DEBIAN" patch="1">DSA-467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12929" source="XF" adv="1">ecartis-subscribe-password-disclosure(12929)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0782" published="2004-05-04" name="CVE-2003-0782" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-467" source="DEBIAN" patch="1">DSA-467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12928" source="XF" adv="1">ecartis-multiple-bo(12928)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0783" published="2003-10-06" name="CVE-2003-0783" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8656" source="BID" patch="1" adv="1">8656</ref>
      <ref url="http://www.debian.org/security/2003/dsa-385" source="DEBIAN" patch="1" adv="1">DSA-385</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106424495804417&amp;w=2" source="BUGTRAQ">20030921 Fw: 0x333hztty => hztty 2.0 local root exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13243" source="XF">hztty-bo(13243)</ref>
      <ref url="http://www.osvdb.org/7119" source="OSVDB">7119</ref>
      <ref url="http://securitytracker.com/id?1007757" source="SECTRACK">1007757</ref>
      <ref url="http://securitytracker.com/id?1007756" source="SECTRACK">1007756</ref>
      <ref url="http://secunia.com/advisories/9792" source="SECUNIA">9792</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yongguang_zhang" name="hztty">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0784" published="2003-10-06" name="CVE-2003-0784" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY47764&amp;apar=only" source="AIXAPAR">IY47764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0785" published="2003-10-06" name="CVE-2003-0785" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-389" source="DEBIAN" patch="1" adv="1">DSA-389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brian_bassett" name="ipmasq">
        <vers num="3.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0786" published="2003-11-17" name="CVE-2003-0786" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602204" source="CERT-VN">VU#602204</ref>
      <ref url="http://www.openssh.com/txt/sshpam.adv" source="CONFIRM">http://www.openssh.com/txt/sshpam.adv</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html" source="FULLDISC">20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://www.securityfocus.com/bid/8677" source="BID">8677</ref>
      <ref url="http://www.securityfocus.com/archive/1/338617" source="BUGTRAQ">20030923 Multiple PAM vulnerabilities in portable OpenSSH</ref>
      <ref url="http://www.securityfocus.com/archive/1/338616" source="BUGTRAQ">20030923 Portable OpenSSH 3.7.1p2 released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.7.1" />
        <vers num="3.7.1p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0787" published="2003-11-17" name="CVE-2003-0787" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/209807" source="CERT-VN">VU#209807</ref>
      <ref url="http://www.openssh.com/txt/sshpam.adv" source="CONFIRM">http://www.openssh.com/txt/sshpam.adv</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html" source="FULLDISC">20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://www.securityfocus.com/bid/8677" source="BID">8677</ref>
      <ref url="http://www.securityfocus.com/archive/1/338617" source="BUGTRAQ">20030923 Multiple PAM vulnerabilities in portable OpenSSH</ref>
      <ref url="http://www.securityfocus.com/archive/1/338616" source="BUGTRAQ">20030923 Portable OpenSSH 3.7.1p2 released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.7.1" />
        <vers num="3.7.1p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0788" published="2003-12-01" name="CVE-2003-0788" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8952" source="BID" patch="1" adv="1">8952</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-275.html" source="REDHAT" patch="1" adv="1">RHSA-2003:275</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13584" source="XF">cups-ipp-dos(13584)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-63.txt" source="TURBO">TLSA-2003-63</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:104" source="MANDRAKE">MDKSA-2003:104</ref>
      <ref url="http://secunia.com/advisories/10123" source="SECUNIA">10123</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000788" source="CONECTIVA">CLA-2003:788</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000779" source="CONECTIVA">CLA-2003:779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0789" published="2003-11-03" name="CVE-2003-0789" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-320.html" source="REDHAT" patch="1" adv="1">RHSA-2003:320</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106761802305141&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031031 GLSA:  apache (200310-04)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13552" source="XF">apache-modcgi-info-disclosure(13552)</ref>
      <ref url="http://www.securityfocus.com/bid/8926" source="BID">8926</ref>
      <ref url="http://www.securityfocus.com/advisories/6079" source="HP">HPSBUX0311-301</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103" source="MANDRAKE">MDKSA-2003:103</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-015.shtml" source="CIAC">O-015</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200310-04.xml" source="GENTOO">200310-04</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000775" source="CONECTIVA">CLA-2003:775</ref>
      <ref url="http://apache.secsup.org/dist/httpd/Announcement2.html" source="CONFIRM" adv="1">http://apache.secsup.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="2.0.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0790" reject="1" published="2003-11-17" name="CVE-2003-0790" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: the reported issue is not a vulnerability or exposure.  Notes: This candidate was assigned to a "head-reading" bug in a component of fetchmail 6.2.4 and earlier, which was claimed to allow a denial of service.  However, the bug is in a broken component of fetchmail that is not "reachable" by any execution path, so it cannot be triggered by any sort of attack and is not exploitable.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0791" published="2003-10-07" name="CVE-2003-0791" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=221526" source="MISC" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=221526</ref>
      <ref url="http://www.securityfocus.com/bid/9322" source="BID" patch="1" adv="1">9322</ref>
      <ref url="http://www.securityfocus.com/advisories/6979" source="SCO" patch="1" adv="1">SCOSA-2004.8</ref>
      <ref url="http://www.osvdb.org/8390" source="OSVDB" patch="1" adv="1">8390</ref>
      <ref url="http://secunia.com/advisories/11103/" source="SECUNIA" patch="1" adv="1">11103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" source="MANDRAKE">MDKSA-2004:021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0792" published="2003-11-17" name="CVE-2003-0792" modified="2011-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13450" source="XF" patch="1" adv="1">fetchmail-email-dos(13450)</ref>
      <ref url="http://www.securityfocus.com/bid/8843" source="BID" patch="1" adv="1">8843</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-61.txt" source="TURBO">TLSA-2003-61</ref>
      <ref url="http://www.securityfocus.com/advisories/5987" source="IMMUNIX">IMNX-2003-7+-023-01</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:101" source="MANDRAKE">MDKSA-2003:101</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-10.xml" source="GENTOO" adv="1">GLSA-200403-10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107731542827401&amp;w=2" source="BUGTRAQ" adv="1">20040220 LNSA-#2004-0002: Fetchmail 6.2.4 and earlier remote denial of service</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-004.0/CSSA-2004-004.0.txt" source="SCO">CSSA-2004-004.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.5.4" />
        <vers num="4.5.5" />
        <vers num="4.5.6" />
        <vers num="4.5.7" />
        <vers num="4.5.8" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.6.2" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="4.6.5" />
        <vers num="4.6.6" />
        <vers num="4.6.7" />
        <vers num="4.6.8" />
        <vers num="4.6.9" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.7.3" />
        <vers num="4.7.4" />
        <vers num="4.7.5" />
        <vers num="4.7.6" />
        <vers num="4.7.7" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.1.0" />
        <vers num="5.1.4" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.0" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers num="5.5.0" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.6.0" />
        <vers num="5.7.0" />
        <vers num="5.7.2" />
        <vers num="5.7.4" />
        <vers num="5.8" />
        <vers num="5.8.1" />
        <vers num="5.8.11" />
        <vers num="5.8.13" />
        <vers num="5.8.14" />
        <vers num="5.8.17" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.0" />
        <vers num="5.9.10" />
        <vers num="5.9.11" />
        <vers num="5.9.13" />
        <vers num="5.9.4" />
        <vers num="5.9.5" />
        <vers num="5.9.8" />
        <vers num="6.0.0" />
        <vers num="6.1.0" />
        <vers num="6.1.3" />
        <vers num="6.2.0" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers prev="1" num="6.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0793" published="2003-11-17" name="CVE-2003-0793" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13447" source="XF" patch="1" adv="1">gdm-dos(13447)</ref>
      <ref url="http://www.securityfocus.com/bid/8846" source="BID" patch="1" adv="1">8846</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000766" source="CONECTIVA">CLA-2003:766</ref>
      <ref url="http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome" source="CONFIRM">http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:100" source="MANDRAKE">MDKSA-2003:100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.2.5.4" />
        <vers num="2.4.1" />
        <vers num="2.4.1.1" />
        <vers num="2.4.1.2" />
        <vers num="2.4.1.3" />
        <vers num="2.4.1.4" />
        <vers num="2.4.1.5" />
        <vers num="2.4.1.6" />
        <vers num="2.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0794" published="2003-11-17" name="CVE-2003-0794" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13448" source="XF" patch="1" adv="1">gdm-command-dos(13448)</ref>
      <ref url="http://www.securityfocus.com/bid/8846" source="BID" patch="1" adv="1">8846</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000766" source="CONECTIVA">CLA-2003:766</ref>
      <ref url="http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome" source="CONFIRM">http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:100" source="MANDRAKE">MDKSA-2003:100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.2.5.4" />
        <vers num="2.4.1" />
        <vers num="2.4.1.1" />
        <vers num="2.4.1.2" />
        <vers num="2.4.1.3" />
        <vers num="2.4.1.4" />
        <vers num="2.4.1.5" />
        <vers num="2.4.1.6" />
        <vers num="2.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0795" published="2003-12-15" name="CVE-2003-0795" modified="2011-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-307.html" source="REDHAT" patch="1" adv="1">RHSA-2003:307</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-305.html" source="REDHAT" patch="1" adv="1">RHSA-2003:305</ref>
      <ref url="http://www.debian.org/security/2004/dsa-415" source="DEBIAN" patch="1" adv="1">DSA-415</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106883387304266&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031114 Quagga remote vulnerability</ref>
      <ref url="http://secunia.com/advisories/10563" source="SECUNIA" adv="1">10563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zebra">
        <vers num="0.91a" />
        <vers num="0.92a" />
        <vers num="0.93a" />
        <vers num="0.93b" />
      </prod>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.1" />
        <vers num="0.96.2" />
        <vers prev="1" num="0.96.3" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.2.1" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0796" published="2004-03-29" name="CVE-2003-0796" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13807" source="XF" patch="1" adv="1">rpcmountd-mount-gain-access(13807)</ref>
      <ref url="http://www.securityfocus.com/bid/9085" source="BID" adv="1">9085</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031102-02-P.asc" source="SGI">20031102-02-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031102-01-P.asc" source="SGI">20031102-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0797" published="2004-03-29" name="CVE-2003-0797" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13808" source="XF" patch="1" adv="1">rpcmountd-dos(13808)</ref>
      <ref url="http://www.securityfocus.com/bid/9084" source="BID" adv="1">9084</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031102-02-P.asc" source="SGI">20031102-02-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031102-01-P.asc" source="SGI">20031102-01-P</ref>
      <ref url="http://www.osvdb.org/8520" source="OSVDB">8520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0801" published="2003-10-06" name="CVE-2003-0801" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a091503-1.txt" source="ATSTAKE" adv="1">A091503-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="electronic_documentation">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0802" published="2003-10-06" name="CVE-2003-0802" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a091503-1.txt" source="ATSTAKE" adv="1">A091503-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="electronic_documentation">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0803" published="2003-10-06" name="CVE-2003-0803" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a091503-1.txt" source="ATSTAKE" adv="1">A091503-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="electronic_documentation">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0804" published="2003-11-17" name="CVE-2003-0804" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc" source="SGI">20040502-01-P</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:14.arp.asc" source="FREEBSD">FreeBSD-SA-03:14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.6.2" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" edition="pre-release" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0805" published="2003-10-06" name="CVE-2003-0805" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-387" source="DEBIAN" patch="1" adv="1">DSA-387</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106123498310717&amp;w=2" source="BUGTRAQ">20030818 FW: [gopher] UMN Gopher 3.0.6 released</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105804485302211&amp;w=2" source="BUGTRAQ">20030712 UMN gopherd[2.x.x/3.x.x]: ftp gateway, and GSisText() buffer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopherd">
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0806" published="2004-06-01" name="CVE-2003-0806" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/471260" source="CERT-VN" patch="1" adv="1">VU#471260</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15702" source="XF">win-winlogon-bo(15702)</ref>
      <ref url="http://www.securityfocus.com/bid/10126" source="BID">10126</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:896" source="OVAL" sig="1">oval:org.mitre.oval:def:896</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:895" source="OVAL" sig="1">oval:org.mitre.oval:def:895</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1054" source="OVAL" sig="1">oval:org.mitre.oval:def:1054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0807" published="2004-06-01" name="CVE-2003-0807" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/698564" source="CERT-VN" patch="1" adv="1">VU#698564</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15709" source="XF">win-cis-rpc-http-dos(15709)</ref>
      <ref url="http://www.securityfocus.com/bid/10123" source="BID">10123</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" source="MS">MS04-012</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-115.shtml" source="CIAC">O-115</ref>
      <ref url="http://securitytracker.com/alerts/2004/Apr/1009762.html" source="SECTRACK">1009762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:995" source="OVAL" sig="1">oval:org.mitre.oval:def:995</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:969" source="OVAL" sig="1">oval:org.mitre.oval:def:969</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1030" source="OVAL" sig="1">oval:org.mitre.oval:def:1030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0809" published="2003-11-17" name="CVE-2003-0809" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8565" source="BID" patch="1" adv="1">8565</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-040.asp" source="MS" patch="1" adv="1">MS03-040</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13300" source="XF">ie-xmlobject-code-execution (13300)</ref>
      <ref url="http://www.osvdb.org/7887" source="OSVDB">7887</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:123" source="OVAL" sig="1">oval:org.mitre.oval:def:123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0812" published="2003-12-15" name="CVE-2003-0812" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/567620" source="CERT-VN" patch="1" adv="1">VU#567620</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-28.html" source="CERT">CA-2003-28</ref>
      <ref url="http://www.securityfocus.com/bid/9011" source="BID" patch="1" adv="1">9011</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-049.asp" source="MS" patch="1" adv="1">MS03-049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106859247713009&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031111 EEYE: Windows Workstation Service Remote Buffer Overflow</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040129-ms03-049.shtml" source="CISCO">20040129 Buffer Overrun in Microsoft Windows 2000 Workstation Service (MS03-049)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106865197102041&amp;w=2" source="BUGTRAQ">20031112 Proof of concept for Windows Workstation Service overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:575" source="OVAL" sig="1">oval:org.mitre.oval:def:575</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:331" source="OVAL" sig="1">oval:org.mitre.oval:def:331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0813" published="2003-11-17" name="CVE-2003-0813" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/547820" source="CERT-VN" patch="1" adv="1">VU#547820</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/155" source="ISS" patch="1" adv="1">20031014 Microsoft RPC Race Condition Denial of Service</ref>
      <ref url="http://www.securitylab.ru/_exploits/rpc2.c.txt" source="MISC">http://www.securitylab.ru/_exploits/rpc2.c.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106579825211708&amp;w=2" source="BUGTRAQ" adv="1">20031010 Bad news on RPC DCOM vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.html" source="FULLDISC">20031011 Bad news on RPC DCOM2 vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.html" source="FULLDISC">20031010 Re: Bad news on RPC DCOM vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.html" source="FULLDISC">20031010 Re : [VERY] BAD news on RPC DCOM Exploit</ref>
      <ref url="http://www.securityfocus.com/bid/8811" source="BID">8811</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-012.mspx" source="MS">MS04-012</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106580303918155&amp;w=2" source="NTBUGTRAQ">20031010 Bad news on RPC DCOM vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106588827513795&amp;w=2" source="BUGTRAQ">20031011 RE: Bad news on RPC DCOM vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:900" source="OVAL" sig="1">oval:org.mitre.oval:def:900</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:894" source="OVAL" sig="1">oval:org.mitre.oval:def:894</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:893" source="OVAL" sig="1">oval:org.mitre.oval:def:893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0814" published="2004-02-03" name="CVE-2003-0814" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/326412" source="CERT-VN" patch="1" adv="1">VU#326412</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-048.asp" source="MS" patch="1" adv="1">MS03-048</ref>
      <ref url="http://www.securityfocus.com/archive/1/337086" source="BUGTRAQ">20030911 LiuDieYu's missing files are here.</ref>
      <ref url="http://www.safecenter.net/liudieyu/BodyRefreshLoadsJPU/BodyRefreshLoadsJPU-Content.htm" source="MISC">http://www.safecenter.net/liudieyu/BodyRefreshLoadsJPU/BodyRefreshLoadsJPU-Content.htm</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0177.html" source="BUGTRAQ">20030910 MSIE->BodyRefreshLoadsJPU:refresh is a new navigation method</ref>
      <ref url="http://securitytracker.com/id?1007687" source="SECTRACK">1007687</ref>
      <ref url="http://secunia.com/advisories/10192" source="SECUNIA">10192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:392" source="OVAL" sig="1">oval:org.mitre.oval:def:392</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:349" source="OVAL" sig="1">oval:org.mitre.oval:def:349</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:344" source="OVAL" sig="1">oval:org.mitre.oval:def:344</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:343" source="OVAL" sig="1">oval:org.mitre.oval:def:343</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:342" source="OVAL" sig="1">oval:org.mitre.oval:def:342</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:341" source="OVAL" sig="1">oval:org.mitre.oval:def:341</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:335" source="OVAL" sig="1">oval:org.mitre.oval:def:335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0815" published="2004-02-03" name="CVE-2003-0815" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9014" source="BID" patch="1" adv="1">9014</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-048.asp" source="MS" patch="1" adv="1">MS03-048</ref>
      <ref url="http://www.securityfocus.com/archive/1/337086" source="BUGTRAQ">20030911 LiuDieYu's missing files are here.</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13676" source="XF">ie-pointer-zone-bypass(13676)</ref>
      <ref url="http://www.osvdb.org/7889" source="OSVDB">7889</ref>
      <ref url="http://www.osvdb.org/7888" source="OSVDB">7888</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html" source="BUGTRAQ">20030910 MSIE->LinkillerSaveRef:another caller-based authorization</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-021.shtml" source="CIAC">O-021</ref>
      <ref url="http://securitytracker.com/id?1007687" source="SECTRACK">1007687</ref>
      <ref url="http://secunia.com/advisories/10192" source="SECUNIA">10192</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106322542104656&amp;w=2" source="BUGTRAQ">20030910 MSIE->Findeath: break caller-based authorization</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106321757619047&amp;w=2" source="BUGTRAQ">20030910 MSIE->LinkillerJPU:another caller-based authorization(is broken).</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:472" source="OVAL" sig="1">oval:org.mitre.oval:def:472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:359" source="OVAL" sig="1">oval:org.mitre.oval:def:359</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:357" source="OVAL" sig="1">oval:org.mitre.oval:def:357</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:356" source="OVAL" sig="1">oval:org.mitre.oval:def:356</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:353" source="OVAL" sig="1">oval:org.mitre.oval:def:353</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:352" source="OVAL" sig="1">oval:org.mitre.oval:def:352</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:351" source="OVAL" sig="1">oval:org.mitre.oval:def:351</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0816" published="2004-02-03" name="CVE-2003-0816" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/652452" source="CERT-VN" patch="1" adv="1">VU#652452</ref>
      <ref url="http://www.kb.cert.org/vuls/id/771604" source="CERT-VN">VU#771604</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-048.asp" source="MS" patch="1" adv="1">MS03-048</ref>
      <ref url="http://www.securityfocus.com/archive/1/337086" source="BUGTRAQ">20030911 LiuDieYu's missing files are here.</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm</ref>
      <ref url="http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM" source="MISC">http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM</ref>
      <ref url="http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM" source="MISC">http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM</ref>
      <ref url="http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM" source="MISC">http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM</ref>
      <ref url="http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM" source="MISC">http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM</ref>
      <ref url="http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM" source="MISC">http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM</ref>
      <ref url="http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM" source="MISC">http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM</ref>
      <ref url="http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm" source="MISC">http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm</ref>
      <ref url="http://www.securityfocus.com/archive/1/336937" source="BUGTRAQ">20030910 MSIE->NAFfileJPU</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html" source="BUGTRAQ">20030910 MSIE->WsOpenJpuInHistory</ref>
      <ref url="http://securitytracker.com/id?1007687" source="SECTRACK">1007687</ref>
      <ref url="http://secunia.com/advisories/10192" source="SECUNIA">10192</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106322240132721&amp;w=2" source="BUGTRAQ">20030910 MSIE->BackMyParent2:Multi-Thread version</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106322063729496&amp;w=2" source="BUGTRAQ">20030910 MSIE->WsBASEjpu</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106321882821788&amp;w=2" source="BUGTRAQ">20030910 MSIE->WsOpenFileJPU</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106321781819727&amp;w=2" source="BUGTRAQ">20030910 MSIE->WsFakeSrc</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106321693517858&amp;w=2" source="BUGTRAQ">20030910 MSIE->NAFjpuInHistory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106321638416884&amp;w=2" source="BUGTRAQ">20030910 MSIE->RefBack</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:479" source="OVAL" sig="1">oval:org.mitre.oval:def:479</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:459" source="OVAL" sig="1">oval:org.mitre.oval:def:459</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:416" source="OVAL" sig="1">oval:org.mitre.oval:def:416</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:409" source="OVAL" sig="1">oval:org.mitre.oval:def:409</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:363" source="OVAL" sig="1">oval:org.mitre.oval:def:363</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:362" source="OVAL" sig="1">oval:org.mitre.oval:def:362</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:361" source="OVAL" sig="1">oval:org.mitre.oval:def:361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0817" published="2004-02-03" name="CVE-2003-0817" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9012" source="BID" patch="1" adv="1">9012</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-048.asp" source="MS" patch="1" adv="1">MS03-048</ref>
      <ref url="http://secunia.com/advisories/10192" source="SECUNIA">10192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:566" source="OVAL" sig="1">oval:org.mitre.oval:def:566</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:556" source="OVAL" sig="1">oval:org.mitre.oval:def:556</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:549" source="OVAL" sig="1">oval:org.mitre.oval:def:549</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:548" source="OVAL" sig="1">oval:org.mitre.oval:def:548</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:543" source="OVAL" sig="1">oval:org.mitre.oval:def:543</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:520" source="OVAL" sig="1">oval:org.mitre.oval:def:520</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:508" source="OVAL" sig="1">oval:org.mitre.oval:def:508</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0818" published="2004-03-03" name="CVE-2003-0818" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-041A.html" source="CERT">TA04-041A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/583108" source="CERT-VN">VU#583108</ref>
      <ref url="http://www.kb.cert.org/vuls/id/216324" source="CERT-VN" adv="1">VU#216324</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-007.asp" source="MS" patch="1" adv="1">MS04-007</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=107650972723080&amp;w=2" source="NTBUGTRAQ">20040210 EEYE: Microsoft ASN.1 Library Bit String Heap Corruption</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=107650972617367&amp;w=2" source="NTBUGTRAQ">20040210 EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643892224825&amp;w=2" source="BUGTRAQ">20040210 EEYE: Microsoft ASN.1 Library Bit String Heap Corruption</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643836125615&amp;w=2" source="BUGTRAQ">20040210 EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:799" source="OVAL" sig="1">oval:org.mitre.oval:def:799</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:797" source="OVAL" sig="1">oval:org.mitre.oval:def:797</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:796" source="OVAL" sig="1">oval:org.mitre.oval:def:796</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:653" source="OVAL" sig="1">oval:org.mitre.oval:def:653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0819" published="2004-02-17" name="CVE-2003-0819" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.securityfocus.com/bid/9408" source="BID" patch="1" adv="1">9408</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-001.asp" source="MS" patch="1" adv="1">MS04-001</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
      <ref url="http://www.securitytracker.com/id?1008698" source="SECTRACK">1008698</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
      <ref url="http://secunia.com/advisories/10611" source="SECUNIA">10611</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:478" source="OVAL" sig="1">oval:org.mitre.oval:def:478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="proxy_server">
        <vers num="2.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0820" published="2003-12-15" name="CVE-2003-0820" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13682" source="XF" patch="1" adv="1">word-macro-execute-code(13682)</ref>
      <ref url="http://www.securityfocus.com/bid/8835" source="BID" patch="1" adv="1">8835</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-050.asp" source="MS" patch="1" adv="1">MS03-050</ref>
      <ref url="http://www.security.nnov.ru/search/document.asp?docid=5243" source="MISC">http://www.security.nnov.ru/search/document.asp?docid=5243</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0163.html" source="BUGTRAQ" adv="1">20031015 Few issues previously unpublished in English</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:668" source="OVAL" sig="1">oval:org.mitre.oval:def:668</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:586" source="OVAL" sig="1">oval:org.mitre.oval:def:586</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:585" source="OVAL" sig="1">oval:org.mitre.oval:def:585</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:336" source="OVAL" sig="1">oval:org.mitre.oval:def:336</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::chinese" />
        <vers num="2000" edition="::japanese" />
        <vers num="2000" edition="::korean" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2000" edition="sr1a" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="97" edition="" />
        <vers num="97" edition=":" />
        <vers num="97" edition="::japanese" />
        <vers num="97" edition="::chinese" />
        <vers num="97" edition="::korean" />
        <vers num="97" edition="sr1" />
        <vers num="97" edition="sr2" />
        <vers num="98" edition="" />
        <vers num="98" edition=":" />
        <vers num="98" edition="::chinese" />
        <vers num="98" edition="::japanese" />
        <vers num="98" edition="::korean" />
        <vers num="98" edition="sr1" />
        <vers num="98" edition="sr1:" />
        <vers num="98" edition="sr1::japanese" />
        <vers num="98" edition="sr2" />
        <vers num="98" edition="sr2:" />
        <vers num="98" edition="sr2::japanese" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0821" published="2003-12-15" name="CVE-2003-0821" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13681" source="XF" patch="1" adv="1">excel-macro-execute-code (13681) </ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-050.asp" source="MS" patch="1" adv="1">MS03-050</ref>
      <ref url="http://www.securityfocus.com/bid/9010" source="BID">9010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:695" source="OVAL" sig="1">oval:org.mitre.oval:def:695</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:675" source="OVAL" sig="1">oval:org.mitre.oval:def:675</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:636" source="OVAL" sig="1">oval:org.mitre.oval:def:636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::chinese" />
        <vers num="2000" edition="::japanese" />
        <vers num="2000" edition="::korean" />
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2000" edition="sr1a" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="97" edition="" />
        <vers num="97" edition=":" />
        <vers num="97" edition="::japanese" />
        <vers num="97" edition="::chinese" />
        <vers num="97" edition="::korean" />
        <vers num="97" edition="sr1" />
        <vers num="97" edition="sr2" />
        <vers num="98" edition="" />
        <vers num="98" edition=":" />
        <vers num="98" edition="::chinese" />
        <vers num="98" edition="::japanese" />
        <vers num="98" edition="::korean" />
        <vers num="98" edition="sr1" />
        <vers num="98" edition="sr1:" />
        <vers num="98" edition="sr1::japanese" />
        <vers num="98" edition="sr2" />
        <vers num="98" edition="sr2:" />
        <vers num="98" edition="sr2::japanese" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0822" published="2003-12-15" name="CVE-2003-0822" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/279156" source="CERT-VN">VU#279156</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13674" source="XF" patch="1" adv="1">fpse-debug-bo(13674)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-051.asp" source="MS" patch="1" adv="1">MS03-051</ref>
      <ref url="http://secunia.com/advisories/10195" source="SECUNIA">10195</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106865318904055&amp;w=2" source="BUGTRAQ" adv="1">20031112 Frontpage Extensions Remote Command Execution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106862654906759&amp;w=2" source="NTBUGTRAQ">20031112 Frontpage Extensions Remote Command Execution</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:743" source="OVAL" sig="1">oval:org.mitre.oval:def:743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:699" source="OVAL" sig="1">oval:org.mitre.oval:def:699</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:367" source="OVAL" sig="1">oval:org.mitre.oval:def:367</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:366" source="OVAL" sig="1">oval:org.mitre.oval:def:366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:364" source="OVAL" sig="1">oval:org.mitre.oval:def:364</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage_server_extensions">
        <vers num="2000" />
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_team_services">
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0823" published="2004-02-03" name="CVE-2003-0823" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/413886" source="CERT-VN">VU#413886</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-048.asp" source="MS" patch="1" adv="1">MS03-048</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106322197932006&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030910 MSIE->HijackClick: 1+1=2</ref>
      <ref url="http://www.securityfocus.com/archive/1/337086" source="BUGTRAQ">20030911 LiuDieYu's missing files are here.</ref>
      <ref url="http://www.securitytracker.com/id?1006036" source="SECTRACK">1006036</ref>
      <ref url="http://secunia.com/advisories/10192" source="SECUNIA">10192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:733" source="OVAL" sig="1">oval:org.mitre.oval:def:733</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:588" source="OVAL" sig="1">oval:org.mitre.oval:def:588</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:372" source="OVAL" sig="1">oval:org.mitre.oval:def:372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:371" source="OVAL" sig="1">oval:org.mitre.oval:def:371</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:370" source="OVAL" sig="1">oval:org.mitre.oval:def:370</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:369" source="OVAL" sig="1">oval:org.mitre.oval:def:369</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:368" source="OVAL" sig="1">oval:org.mitre.oval:def:368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0824" published="2003-12-15" name="CVE-2003-0824" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/179012" source="CERT-VN">VU#179012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13680" source="XF" patch="1" adv="1">fpse-smarthtml-dos(13680)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-051.asp" source="MS" patch="1" adv="1">MS03-051</ref>
      <ref url="http://secunia.com/advisories/10195" source="SECUNIA">10195</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:762" source="OVAL" sig="1">oval:org.mitre.oval:def:762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:625" source="OVAL" sig="1">oval:org.mitre.oval:def:625</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:606" source="OVAL" sig="1">oval:org.mitre.oval:def:606</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:591" source="OVAL" sig="1">oval:org.mitre.oval:def:591</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:308" source="OVAL" sig="1">oval:org.mitre.oval:def:308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage_server_extensions">
        <vers num="2000" />
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_team_services">
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0825" published="2004-03-03" name="CVE-2003-0825" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/445214" source="CERT-VN">VU#445214</ref>
      <ref url="http://www.securityfocus.com/bid/9624" source="BID" patch="1" adv="1">9624</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-006.asp" source="MS" patch="1" adv="1">MS04-006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15037" source="XF">win-wins-gsflag-dos(15037)</ref>
      <ref url="http://www.osvdb.org/3903" source="OSVDB">3903</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-077.shtml" source="CIAC">O-077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:802" source="OVAL" sig="1">oval:org.mitre.oval:def:802</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:801" source="OVAL" sig="1">oval:org.mitre.oval:def:801</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:800" source="OVAL" sig="1">oval:org.mitre.oval:def:800</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:704" source="OVAL" sig="1">oval:org.mitre.oval:def:704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0826" published="2003-10-06" name="CVE-2003-0826" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106407188509874&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030920 LSH: Buffer overrun and remote root compromise in lshd</ref>
      <ref url="http://www.debian.org/security/2005/dsa-717" source="DEBIAN">DSA-717</ref>
      <ref url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html" source="CONFIRM">http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010496.html" source="FULLDISC">20030919 lsh patch (was Re: [Full-Disclosure] new ssh exploit?)</ref>
      <ref url="http://bugs.debian.org/211662" source="CONFIRM">http://bugs.debian.org/211662</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106398939512178&amp;w=2" source="BUGTRAQ">20030919 Remote root vuln in lsh 1.4.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="lsh">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0827" published="2003-10-06" name="CVE-2003-0827" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106399616919636&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030919 AppSecInc Security Alert: Denial of Service Vulnerability in DB2 Discovery Service</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY47686&amp;apar=only" source="AIXAPAR">IY47686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":linux" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0828" published="2004-03-29" name="CVE-2003-0828" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13301" source="XF" patch="1" adv="1">freesweep-bo(13301)</ref>
      <ref url="http://www.securityfocus.com/bid/8716" source="BID" patch="1" adv="1">8716</ref>
      <ref url="http://www.debian.org/security/2003/dsa-391" source="DEBIAN" patch="1" adv="1">DSA-391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gus_and_psilord" name="freesweep">
        <vers num="0.88" />
        <vers num="0.90" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0830" published="2003-11-17" name="CVE-2003-0830" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-390" source="DEBIAN" patch="1" adv="1">DSA-390</ref>
    </refs>
    <vuln_soft>
      <prod vendor="marbles" name="marbles">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0831" published="2003-11-17" name="CVE-2003-0831" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/405348" source="CERT-VN">VU#405348</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106441655617816&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030924 [slackware-security]  ProFTPD Security Advisory (SSA:2003-259-02)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12200" source="XF" adv="1">proftpd-ascii-xfer-newline-bo(12200)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/154" source="ISS">20030923 ProFTPD ASCII File Remote Compromise Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:095" source="MANDRAKE">MDKSA-2003:095</ref>
      <ref url="http://secunia.com/advisories/9829" source="SECUNIA">9829 </ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106606885611269&amp;w=2" source="BUGTRAQ">20031013 Remote root exploit for proftpd \n bug</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012072.html" source="FULLDISC">20031014 Another ProFTPd root EXPLOIT ?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.7" />
        <vers num="1.2.7_rc1" />
        <vers num="1.2.7_rc2" />
        <vers num="1.2.7_rc3" />
        <vers num="1.2.8" />
        <vers num="1.2.8_rc1" />
        <vers num="1.2.8_rc2" />
        <vers num="1.2.9_rc1" />
        <vers num="1.2.9_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0832" published="2003-11-17" name="CVE-2003-0832" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-392" source="DEBIAN" patch="1" adv="1">DSA-392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfs" name="webfs">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0833" published="2003-11-17" name="CVE-2003-0833" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-392" source="DEBIAN" patch="1" adv="1">DSA-392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfs" name="webfs">
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0834" published="2003-12-01" name="CVE-2003-0834" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/575804" source="CERT-VN" patch="1" adv="1">VU#575804</ref>
      <ref url="http://www.securityfocus.com/bid/8973" source="BID" patch="1" adv="1">8973</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57414" source="SUNALERT">57414</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q4/0047.html" source="HP">HPSBUX0311-297</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P" source="SGI">20040801-01-P</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=134&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20040825 CDE libDtHelp LOGNAME Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5141" source="OVAL" sig="1">oval:org.mitre.oval:def:5141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_unix">
        <vers num="8.0" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
        <vers num="7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0835" published="2003-11-17" name="CVE-2003-0835" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106454257221455&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030925 MPlayer Security Advisory #01: Remotely exploitable buffer overflow</ref>
      <ref url="http://www.mplayerhq.hu/homepage/design6/news.html" source="CONFIRM">http://www.mplayerhq.hu/homepage/design6/news.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106485005213109&amp;w=2" source="BUGTRAQ">20030929 GLSA:  media-video/mplayer (200309-15)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106460912721618&amp;w=2" source="BUGTRAQ">20030926 Mplayer Buffer Overflow</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000760" source="CONECTIVA">CLA-2003:760</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90" />
        <vers num="0.90_pre" />
        <vers num="0.90_rc" />
        <vers num="0.90_rc4" />
        <vers num="0.91" />
        <vers num="1.0_pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0836" published="2003-11-17" name="CVE-2003-0836" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":aix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0837" published="2003-11-17" name="CVE-2003-0837" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8743" source="BID" patch="1" adv="1">8743</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13331" source="XF">db2-invoke-bo(13331)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106503709914622&amp;w=2" source="BUGTRAQ">20031001 ptl-2003-02: IBM DB2 INVOKE Command Stack Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0838" published="2003-11-17" name="CVE-2003-0838" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-040.asp" source="MS">MS03-040</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html" source="MISC">http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106304733121753&amp;w=2" source="BUGTRAQ" adv="1">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009639.html" source="FULLDISC">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13314" source="XF">ie-popup-code-execution(13314)</ref>
      <ref url="http://www.securityfocus.com/bid/8556" source="BID">8556</ref>
      <ref url="http://www.osvdb.org/7872" source="OSVDB">7872</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0310&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=2169" source="NTBUGTRAQ">20031001 DNS/Hosts file issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106302799428500&amp;w=2" source="NTBUGTRAQ">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106304876523459&amp;w=2" source="BUGTRAQ">20030908 Temporary Fix for IE Zero Day Malware RE: BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:204" source="OVAL" sig="1">oval:org.mitre.oval:def:204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0839" published="2003-11-17" name="CVE-2003-0839" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.geocities.co.jp/SiliconValley/1667/advisory08e.html" source="MISC">http://www.geocities.co.jp/SiliconValley/1667/advisory08e.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106563075612028&amp;w=2" source="BUGTRAQ" adv="1">20031008 Microsoft Windows Server 2003 "Shell Folders" Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0840" published="2003-11-17" name="CVE-2003-0840" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106563181313571&amp;w=2" source="BUGTRAQ" adv="1">20031008 HPUX dtprintinfo buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0841" published="2003-11-17" name="CVE-2003-0841" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106554919000847&amp;w=2" source="BUGTRAQ" adv="1">20031007 PeopleSoft Grid Option Vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0842" published="2003-11-17" name="CVE-2003-0842" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105457180009860&amp;w=2" source="BUGTRAQ" adv="1">20030601 Mod_gzip Debug Mode Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dag_apt_repository" name="mod_gzip">
        <vers num="1.3.26.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0843" published="2003-11-17" name="CVE-2003-0843" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105457180009860&amp;w=2" source="BUGTRAQ" adv="1">20030601 Mod_gzip Debug Mode Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dag_apt_repository" name="mod_gzip">
        <vers prev="1" num="1.3.26.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0844" published="2003-11-17" name="CVE-2003-0844" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105457180009860&amp;w=2" source="BUGTRAQ" adv="1">20030601 Mod_gzip Debug Mode Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dag_apt_repository" name="mod_gzip">
        <vers prev="1" num="1.3.26.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0845" published="2003-11-17" name="CVE-2003-0845" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8773" source="BID" patch="1" adv="1">8773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11300" source="OVAL">oval:org.mitre.oval:def:11300</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106546044416498&amp;w=2" source="BUGTRAQ" adv="1">20031005 JBoss 3.2.1: Remote Command Injection</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-1048.html" source="REDHAT">RHSA-2007:1048</ref>
      <ref url="http://sourceforge.net/docman/display_doc.php?docid=19314&amp;group_id=22866" source="CONFIRM">http://sourceforge.net/docman/display_doc.php?docid=19314&amp;group_id=22866</ref>
      <ref url="http://secunia.com/advisories/27914" source="SECUNIA">27914</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106547728803252&amp;w=2" source="BUGTRAQ">20031006 Update JBoss 308 &amp; 321: Remote Command Injection</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0846" published="2003-11-17" name="CVE-2003-0846" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106546177518140&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031006 Local root exploit in SuSE Linux 7.3Pro</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106546531922379&amp;w=2" source="BUGTRAQ">20031006 Re: Local root exploit in SuSE Linux 8.2Pro</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0847" published="2003-11-17" name="CVE-2003-0847" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106545972615578&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031006 Local root exploit in SuSE Linux 8.2Pro</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106546531922379&amp;w=2" source="BUGTRAQ">20031006 Re: Local root exploit in SuSE Linux 8.2Pro</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0848" published="2003-11-17" name="CVE-2003-0848" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-428" source="DEBIAN" patch="1" adv="1">DSA-428</ref>
      <ref url="http://www.trustix.org/errata/misc/2004/TSL-2004-0005-slocate.asc.txt" source="TRUSTIX">2004-0005</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-041.html" source="REDHAT">RHSA-2004:041</ref>
      <ref url="http://www.ebitech.sk/patrik/SA/SA-20031006.txt" source="MISC">http://www.ebitech.sk/patrik/SA/SA-20031006.txt</ref>
      <ref url="http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt" source="MISC">http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11033" source="OVAL">oval:org.mitre.oval:def:11033</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106589631819348&amp;w=2" source="BUGTRAQ" adv="1">20031011 SA-20031006 slocate buffer overflow - exploitation proof</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106546447321274&amp;w=2" source="BUGTRAQ" adv="1">20031006 SA-20031006 slocate vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2004-001.0/CSSA-2004-001.0.txt" source="SCO">CSSA-2004-001.0</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00009.html" source="FEDORA">FEDORA-2004-059</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:004" source="MANDRAKE">MDKSA-2004:004</ref>
      <ref url="http://secunia.com/advisories/9962/" source="SECUNIA">9962</ref>
      <ref url="http://secunia.com/advisories/10722" source="SECUNIA">10722</ref>
      <ref url="http://secunia.com/advisories/10720" source="SECUNIA">10720</ref>
      <ref url="http://secunia.com/advisories/10702" source="SECUNIA">10702</ref>
      <ref url="http://secunia.com/advisories/10698" source="SECUNIA">10698</ref>
      <ref url="http://secunia.com/advisories/10686" source="SECUNIA">10686</ref>
      <ref url="http://secunia.com/advisories/10683" source="SECUNIA">10683</ref>
      <ref url="http://secunia.com/advisories/10670" source="SECUNIA">10670</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-040.html" source="REDHAT">RHSA-2004:040</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:821" source="OVAL" sig="1">oval:org.mitre.oval:def:821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0849" published="2003-11-17" name="CVE-2003-0849" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106451047819552&amp;w=2" source="BUGTRAQ" adv="1">20030925 Cfengine2 cfservd remote stack overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106546086216984&amp;w=2" source="BUGTRAQ">20031005 GLSA: cfengine (200310-02)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106485375218280&amp;w=2" source="BUGTRAQ">20030928 cfengine2-2.0.3 remote exploit for redhat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cfengine">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" edition="b1" />
        <vers num="2.0.5" edition="pre" />
        <vers num="2.0.5" edition="pre2" />
        <vers num="2.0.6" />
        <vers num="2.0.7" edition="p1" />
        <vers num="2.0.7" edition="p2" />
        <vers num="2.0.7" edition="p3" />
        <vers num="2.1.0" edition="a6" />
        <vers num="2.1.0" edition="a8" />
        <vers num="2.1.0" edition="a9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0850" published="2003-11-17" name="CVE-2003-0850" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-410" source="DEBIAN" patch="1" adv="1">DSA-410</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106728224210446&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031027 Libnids &lt;= 1.17 buffer overflow</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=191323" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=191323</ref>
      <ref url="http://secunia.com/advisories/10543" source="SECUNIA">10543</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000773" source="CONECTIVA">CLA-2003:773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dug_song" name="dsniff">
        <vers num="2.3" />
      </prod>
      <prod vendor="rafal_wojtczuk" name="libnids">
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.16" />
        <vers num="1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0851" published="2003-12-01" name="CVE-2003-0851" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/412478" source="CERT-VN" patch="1" adv="1">VU#412478</ref>
      <ref url="http://www.securityfocus.com/bid/8970" source="BID" patch="1" adv="1">8970</ref>
      <ref url="http://www.openssl.org/news/secadv_20031104.txt" source="CONFIRM" patch="1" adv="1">http://www.openssl.org/news/secadv_20031104.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106796246511667&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031104 [OpenSSL Advisory] Denial of Service in ASN.1 parsing</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030930-ssl.shtml" source="CISCO">20030930 SSL Implementation Vulnerabilities</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-119.html" source="REDHAT">RHSA-2004:119</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5528" source="OVAL">oval:org.mitre.oval:def:5528</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc" source="SGI">20040304-01-U</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.asc" source="NETBSD">NetBSD-SA2004-003</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html" source="FEDORA">FEDORA-2005-1042</ref>
      <ref url="http://secunia.com/advisories/17381" source="SECUNIA">17381</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403850228012&amp;w=2" source="BUGTRAQ">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111" />
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.7" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e" />
        <vers num="12.1(11b)e" />
        <vers num="12.2sx" />
        <vers num="12.2sy" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.0(3)" />
        <vers num="6.0(4)" />
        <vers num="6.0(4.101)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(2)" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1(5)" />
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.3(1)" />
        <vers num="6.3(3.102)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0852" published="2003-11-17" name="CVE-2003-0852" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8877" source="BID" patch="1" adv="1">8877</ref>
      <ref url="http://www.guninski.com/sylph.html" source="MISC">http://www.guninski.com/sylph.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012542.html" source="FULLDISC">20031022 Sylpheed-claws format string bug, yet still sylpheed much better than windows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13508" source="XF">sylpheed-smtp-format-string(13508)</ref>
      <ref url="http://sylpheed.good-day.net/#changes" source="CONFIRM">http://sylpheed.good-day.net/#changes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sylpheed" name="sylpheed">
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
      </prod>
      <prod vendor="sylpheed-claws" name="sylpheed-claws">
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0853" published="2003-11-17" name="CVE-2003-0853" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8875" source="BID" patch="1" adv="1">8875</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-60.txt" source="TURBO">TLSA-2003-60</ref>
      <ref url="http://www.securityfocus.com/advisories/6014" source="IMMUNIX">IMNX-2003-7+-026-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-310.html" source="REDHAT">RHSA-2003:310</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-309.html" source="REDHAT">RHSA-2003:309</ref>
      <ref url="http://www.guninski.com/binls.html" source="MISC">http://www.guninski.com/binls.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf</ref>
      <ref url="http://secunia.com/advisories/17069" source="SECUNIA">17069</ref>
      <ref url="http://secunia.com/advisories/10126" source="SECUNIA">10126</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012548.html" source="FULLDISC">20031022 Fun with /bin/ls, yet still ls better than windows</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000771" source="CONECTIVA">CLA-2003:771</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000768" source="CONECTIVA">CLA-2003:768</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:106" source="MANDRAKE">MDKSA-2003:106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="fileutils">
        <vers num="4.0" />
        <vers num="4.0.36" />
        <vers num="4.1" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.1" />
        <vers num="2.4.2_beta18" edition="" />
        <vers num="2.4.2_beta18" edition=":academ" />
        <vers num="2.4.2_beta18_vr10" />
        <vers num="2.4.2_beta18_vr11" />
        <vers num="2.4.2_beta18_vr12" />
        <vers num="2.4.2_beta18_vr13" />
        <vers num="2.4.2_beta18_vr14" />
        <vers num="2.4.2_beta18_vr15" />
        <vers num="2.4.2_beta18_vr4" />
        <vers num="2.4.2_beta18_vr5" />
        <vers num="2.4.2_beta18_vr6" />
        <vers num="2.4.2_beta18_vr7" />
        <vers num="2.4.2_beta18_vr8" />
        <vers num="2.4.2_beta18_vr9" />
        <vers num="2.4.2_beta2" edition="" />
        <vers num="2.4.2_beta2" edition=":academ" />
        <vers num="2.4.2_vr16" />
        <vers num="2.4.2_vr17" />
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0854" published="2003-11-17" name="CVE-2003-0854" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-60.txt" source="TURBO">TLSA-2003-60</ref>
      <ref url="http://www.securityfocus.com/advisories/6014" source="IMMUNIX">IMNX-2003-7+-026-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-310.html" source="REDHAT">RHSA-2003:310</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-309.html" source="REDHAT">RHSA-2003:309</ref>
      <ref url="http://www.guninski.com/binls.html" source="MISC">http://www.guninski.com/binls.html</ref>
      <ref url="http://www.debian.org/security/2005/dsa-705" source="DEBIAN">DSA-705</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf</ref>
      <ref url="http://secunia.com/advisories/17069" source="SECUNIA" adv="1">17069</ref>
      <ref url="http://secunia.com/advisories/10126" source="SECUNIA" adv="1">10126</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012548.html" source="FULLDISC">20031022 Fun with /bin/ls, yet still ls better than windows</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000771" source="CONECTIVA">CLA-2003:771</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000768" source="CONECTIVA">CLA-2003:768</ref>
      <ref url="http://www.milw0rm.com/exploits/115" source="MILW0RM">115</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:106" source="MANDRAKE">MDKSA-2003:106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="fileutils">
        <vers num="4.0" />
        <vers num="4.0.36" />
        <vers num="4.1" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.1" />
        <vers num="2.4.2_beta18" edition="" />
        <vers num="2.4.2_beta18" edition=":academ" />
        <vers num="2.4.2_beta18_vr10" />
        <vers num="2.4.2_beta18_vr11" />
        <vers num="2.4.2_beta18_vr12" />
        <vers num="2.4.2_beta18_vr13" />
        <vers num="2.4.2_beta18_vr14" />
        <vers num="2.4.2_beta18_vr15" />
        <vers num="2.4.2_beta18_vr4" />
        <vers num="2.4.2_beta18_vr5" />
        <vers num="2.4.2_beta18_vr6" />
        <vers num="2.4.2_beta18_vr7" />
        <vers num="2.4.2_beta18_vr8" />
        <vers num="2.4.2_beta18_vr9" />
        <vers num="2.4.2_beta2" edition="" />
        <vers num="2.4.2_beta2" edition=":academ" />
        <vers num="2.4.2_vr16" />
        <vers num="2.4.2_vr17" />
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0855" published="2003-11-03" name="CVE-2003-0855" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=107025" source="CONFIRM" patch="1">http://bugzilla.gnome.org/show_bug.cgi?id=107025</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-312.html" source="REDHAT">RHSA-2003:312</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-311.html" source="REDHAT">RHSA-2003:311</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=107519" source="CONFIRM" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=107519</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="charles_kerr" name="pan">
        <vers prev="1" num="0.13.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0856" published="2003-12-15" name="CVE-2003-0856" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-317.html" source="REDHAT" patch="1" adv="1">RHSA-2003:317</ref>
      <ref url="http://www.debian.org/security/2004/dsa-492" source="DEBIAN" patch="1" adv="1">DSA-492</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-316.html" source="REDHAT">RHSA-2003:316</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00004.html" source="FEDORA">FEDORA-2004-115</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10912" source="OVAL">oval:org.mitre.oval:def:10912</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stephen_hemminger" name="iproute">
        <vers prev="1" num="2.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0857" published="2003-12-31" name="CVE-2003-0857" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=108574" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=108574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0858" published="2003-12-15" name="CVE-2003-0858" modified="2011-03-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-315.html" source="REDHAT" patch="1" adv="1">RHSA-2003:315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-307.html" source="REDHAT" patch="1" adv="1">RHSA-2003:307</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-305.html" source="REDHAT" patch="1" adv="1">RHSA-2003:305</ref>
      <ref url="http://www.debian.org/security/2004/dsa-415" source="DEBIAN" patch="1" adv="1">DSA-415</ref>
      <ref url="http://secunia.com/advisories/10563" source="SECUNIA" adv="1">10563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10169" source="OVAL">oval:org.mitre.oval:def:10169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zebra">
        <vers prev="1" num="0.91" />
      </prod>
      <prod vendor="quagga" name="quagga_routing_software_suite">
        <vers prev="1" num="0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0859" published="2003-12-15" name="CVE-2003-0859" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-325.html" source="REDHAT" patch="1" adv="1">RHSA-2003:325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-334.html" source="REDHAT">RHSA-2003:334</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11337" source="OVAL">oval:org.mitre.oval:def:11337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.3.2" />
      </prod>
      <prod vendor="gnu" name="zebra">
        <vers num="0.91a" />
        <vers num="0.92a" />
        <vers num="0.93a" />
        <vers num="0.93b" />
      </prod>
      <prod vendor="quagga" name="quagga_routing_software_suite">
        <vers num="0.96.2" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.2.1" />
        <vers num="2.3" />
      </prod>
      <prod vendor="intel" name="ia64">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0860" published="2003-11-17" name="CVE-2003-0860" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/release_4_3_3.php" source="CONFIRM" adv="1">http://www.php.net/release_4_3_3.php</ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.3.3" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.3.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0861" published="2003-11-17" name="CVE-2003-0861" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/release_4_3_3.php" source="CONFIRM" adv="1">http://www.php.net/release_4_3_3.php</ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.3.3" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.3.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0862" reject="1" published="2003-11-17" name="CVE-2003-0862" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0813.  Reason: This candidate is a duplicate of CVE-2003-0813.  Notes: All CVE users should reference CVE-2003-0813 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0863" published="2003-11-17" name="CVE-2003-0863" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839111204227" source="BUGTRAQ" adv="1">20030716 PHP safe mode broken?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0864" published="2003-11-17" name="CVE-2003-0864" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8817" source="BID" patch="1" adv="1">8817</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106667431021928&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031019 [OpenPKG-SA-2003.045] OpenPKG Security Advisory (ircd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106606129601446&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031012 buffer overflow in IRCD software</ref>
      <ref url="ftp://ftp.irc.org/irc/server/ChangeLog" source="CONFIRM">ftp://ftp.irc.org/irc/server/ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13408" source="XF">ircd-mjoin-bo(13408)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000765" source="CONECTIVA">CLA-2003:765</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ircnet" name="ircnet_ircd">
        <vers num="2.10" />
        <vers num="2.10.3_p3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0865" published="2003-11-17" name="CVE-2003-0865" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8680" source="BID" patch="1" adv="1">8680</ref>
      <ref url="http://www.debian.org/security/2004/dsa-435" source="DEBIAN" patch="1" adv="1">DSA-435</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106493686331198&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030930 GLSA:  mpg123 (200309-17)</ref>
      <ref url="http://www.securityfocus.com/archive/1/338641" source="BUGTRAQ" adv="1">20030923 mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit.</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt" source="SCO">CSSA-2004-002.0</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000781" source="CONECTIVA">CLA-2003:781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59r" />
        <vers num="0.59s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0866" published="2003-11-17" name="CVE-2003-0866" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8824" source="BID" patch="1" adv="1">8824</ref>
      <ref url="http://www.debian.org/security/2003/dsa-395" source="DEBIAN" patch="1" adv="1">DSA-395</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=215506" source="CONFIRM" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=215506</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1979/references" source="VUPEN">ADV-2008-1979</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13429" source="XF">tomcat-non-http-dos(13429)</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" source="SUNALERT">239312</ref>
      <ref url="http://secunia.com/advisories/30908" source="SECUNIA">30908</ref>
      <ref url="http://secunia.com/advisories/30899" source="SECUNIA">30899</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0867" reject="1" published="2003-11-17" name="CVE-2003-0867" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0662.  Reason: This candidate is a duplicate of CVE-2003-0662.  Notes: All CVE users should reference CVE-2003-0662 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-0870" published="2003-11-17" name="CVE-2003-0870" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13458" source="XF" patch="1" adv="1">opera-escape-heap-overflow(13458)</ref>
      <ref url="http://www.securityfocus.com/bid/8853" source="BID" patch="1" adv="1">8853</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a102003-1.txt" source="ATSTAKE" patch="1" adv="1">A102003-1</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0016.html" source="VULNWATCH">20031020 Opera HREF escaped server name overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.11" />
        <vers num="7.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0871" published="2003-11-03" name="CVE-2003-0871" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8922" source="BID" patch="1" adv="1">8922</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00039.html" source="APPLE">APPLE-SA-2003-10-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0872" published="2003-11-17" name="CVE-2003-0872" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8864" source="BID" patch="1" adv="1">8864</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.27/CSSA-2003-SCO.27.txt" source="SCO" patch="1" adv="1">CSSA-2003-SCO.27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0874" published="2003-11-17" name="CVE-2003-0874" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8856" source="BID" patch="1" adv="1">8856</ref>
      <ref url="http://www.securiteam.com/unixfocus/6R0052K8KM.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/6R0052K8KM.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13391" source="XF">deskpro-multiple-sql-injection(13391)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106667525623311&amp;w=2" source="BUGTRAQ">20031020 Multiple SQL Injection Vulnerabilities in DeskPRO</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html" source="VULNWATCH">20031020 Multiple SQL Injection Vulnerabilities in DeskPRO</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deskpro" name="deskpro">
        <vers num="1.1_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0875" published="2003-11-17" name="CVE-2003-0875" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106123103606336&amp;w=2" source="BUGTRAQ" adv="1">20030818 OpenSLP initscript symlink vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000723" source="CONECTIVA">CLA-2003:723</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openslp" name="openslp">
        <vers prev="1" num="1.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0876" published="2003-11-03" name="CVE-2003-0876" modified="2008-10-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8916" source="BID" patch="1" adv="1">8916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13537" source="XF">macos-insecure-file-permissions(13537)</ref>
      <ref url="http://www.securityfocus.com/bid/8917" source="BID">8917</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a102803-1.txt" source="ATSTAKE">A102803-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0877" published="2003-11-03" name="CVE-2003-0877" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a102803-1.txt" source="ATSTAKE" patch="1" adv="1">A102803-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13542" source="XF">macos-core-files-symlink(13542)</ref>
      <ref url="http://www.securityfocus.com/bid/8917" source="BID">8917</ref>
      <ref url="http://www.securityfocus.com/bid/8914" source="BID" adv="1">8914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0878" published="2003-11-03" name="CVE-2003-0878" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0879" reject="1" published="2003-11-17" name="CVE-2003-0879" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0518.  Reason: This candidate is a reservation duplicate of CVE-2003-0518.  Notes: All CVE users should reference CVE-2003-0518 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0880" published="2003-11-03" name="CVE-2003-0880" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0881" published="2003-11-03" name="CVE-2003-0881" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0882" published="2003-11-03" name="CVE-2003-0882" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0883" published="2003-11-03" name="CVE-2003-0883" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0885" published="2003-12-31" name="CVE-2003-0885" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=41253" source="CONFIRM" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=41253</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286" source="CONFIRM" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xscreensaver" name="xscreensaver">
        <vers num="4.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0886" published="2003-12-01" name="CVE-2003-0886" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-401" source="DEBIAN" patch="1" adv="1">DSA-401</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106858898708752&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031111 HylaFAX - Format String Vulnerability Fixed</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_045_hylafax.html" source="SUSE">SuSE-SA:2003:045</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:105" source="MANDRAKE">MDKSA-2003:105</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000783" source="CONECTIVA">CLA-2003:783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hylafax" name="hylafax">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0887" published="2003-12-31" name="CVE-2003-0887" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?rev=1.6" source="CONFIRM">http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?rev=1.6</ref>
      <ref url="http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?r1=1.4&amp;r2=1.5" source="CONFIRM">http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?r1=1.4&amp;r2=1.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angus_mackay" name="ez-ipupdate">
        <vers num="3.0.11b5" />
        <vers num="3.0.11b7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0894" published="2003-11-17" name="CVE-2003-0894" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/496340" source="CERT-VN">VU#496340</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13451" source="XF">oracle-oracleo-binaries-bo(13451)</ref>
      <ref url="http://www.securityfocus.com/bid/8845" source="BID">8845</ref>
      <ref url="http://www.securityfocus.com/bid/8844" source="BID">8844</ref>
      <ref url="http://securitytracker.com/id?1007956" source="SECTRACK">1007956</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.2.0.4" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0895" published="2003-11-03" name="CVE-2003-0895" modified="2008-10-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13541" source="XF">macos-long-command-bo(13541)</ref>
      <ref url="http://www.securityfocus.com/bid/8913" source="BID" adv="1">8913</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a102803-3.txt" source="ATSTAKE">A102803-3</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0896" published="2003-11-17" name="CVE-2003-0896" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200356-1" source="SUNALERT">200356</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57221" source="SUNALERT">57221</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106692334503819&amp;w=2" source="BUGTRAQ" adv="1">20021023 [LSD] Security vulnerability in SUN's Java Virtual Machine implementation</ref>
      <ref url="http://lsd-pl.net/code/JVM/jre.tar.gz" source="MISC">http://lsd-pl.net/code/JVM/jre.tar.gz</ref>
      <ref url="http://www.securityfocus.com/bid/8879" source="BID">8879</ref>
      <ref url="http://www.securityfocus.com/archive/1/342583" source="BUGTRAQ">20031027 Re: [LSD] Security vulnerability in SUN's Java Virtual Machineimplementation</ref>
      <ref url="http://www.securityfocus.com/archive/1/342580" source="BUGTRAQ">20031027 Re: [LSD] Security vulnerability in SUN's Java Virtual Machine implementation</ref>
      <ref url="http://www.securityfocus.com/advisories/6028" source="HP">HPSBUX0311-295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.4.1" edition="update3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0897" published="2003-11-17" name="CVE-2003-0897" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13558" source="XF" adv="1">winxp-commctl32-code-execution(13558)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106692772510010&amp;w=2" source="BUGTRAQ" adv="1">20031023 Shatter XP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0898" published="2003-11-17" name="CVE-2003-0898" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106010332721672&amp;w=2" source="BUGTRAQ">20030805 Local Vulnerability in IBM DB2 7.1 db2job binary</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":linux" />
        <vers prev="1" num="8.0" edition="" />
        <vers prev="1" num="8.0" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0899" published="2003-11-03" name="CVE-2003-0899" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '&lt;' or '>' characters, which trigger the overflow when the characters are expanded to "&amp;lt;" and "&amp;gt;" sequences.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Acme Labs, thttpd, 2.24</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13530" source="XF" patch="1">thttpd-defang-bo(13530)</ref>
      <ref url="http://www.securityfocus.com/bid/8906" source="BID" patch="1">8906</ref>
      <ref url="http://secunia.com/advisories/10092" source="SECUNIA" patch="1" adv="1">10092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106744982732304&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-396</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106729188224252&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031027 Remote overflow in thttpd</ref>
      <ref url="http://www.osvdb.org/2729" source="OSVDB">2729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="thttpd">
        <vers num="2.21" />
        <vers num="2.21b" />
        <vers num="2.22" />
        <vers num="2.23b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0900" published="2003-12-31" name="CVE-2003-0900" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=108711" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=108711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0901" published="2003-11-03" name="CVE-2003-0901" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8741" source="BID" patch="1" adv="1">8741</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-314.html" source="REDHAT">RHSA-2003:314</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-313.html" source="REDHAT">RHSA-2003:313</ref>
      <ref url="http://www.debian.org/security/2003/dsa-397" source="DEBIAN">DSA-397</ref>
      <ref url="http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c" source="CONFIRM">http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000772" source="CONECTIVA">CLSA-2003:772</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000784" source="CONECTIVA">CLA-2003:784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0902" published="2004-02-03" name="CVE-2003-0902" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-402" source="DEBIAN" patch="1" adv="1">DSA-402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minimalist" name="minimalist">
        <vers num="2.2" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0903" published="2004-02-17" name="CVE-2003-0903" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/139150" source="CERT-VN">VU#139150</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-003.asp" source="MS" patch="1" adv="1">MS04-003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14187" source="XF">mdac-broadcastrequest-bo(14187)</ref>
      <ref url="http://www.securityfocus.com/bid/9407" source="BID" adv="1">9407</ref>
      <ref url="http://www.osvdb.org/3457" source="OSVDB">3457</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:775" source="OVAL" sig="1">oval:org.mitre.oval:def:775</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:751" source="OVAL" sig="1">oval:org.mitre.oval:def:751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:553" source="OVAL" sig="1">oval:org.mitre.oval:def:553</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:525" source="OVAL" sig="1">oval:org.mitre.oval:def:525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0904" published="2004-01-20" name="CVE-2003-0904" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/530660" source="CERT-VN">VU#530660</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13869" source="XF" patch="1" adv="1">exchange-owa-account-access(13869)</ref>
      <ref url="http://www.microsoft.com/exchange/support/e2k3owa.asp" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/exchange/support/e2k3owa.asp</ref>
      <ref url="http://www.securityfocus.com/bid/9409" source="BID">9409</ref>
      <ref url="http://www.securityfocus.com/bid/9118" source="BID" adv="1">9118</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0311&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=9281" source="NTBUGTRAQ" adv="1">20031114 Exchange 2003 OWA major security flaw</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-002.asp" source="MS">MS04-002</ref>
      <ref url="http://secunia.com/advisories/10615" source="SECUNIA">10615</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:477" source="OVAL" sig="1">oval:org.mitre.oval:def:477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_services">
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0905" published="2004-04-15" name="CVE-2003-0905" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/982630" source="CERT-VN">VU#982630</ref>
      <ref url="http://www.securityfocus.com/bid/9825" source="BID" patch="1" adv="1">9825</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-008.asp" source="MS" patch="1" adv="1">MS04-008</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15038" source="XF">win-media-services-dos(15038)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:842" source="OVAL" sig="1">oval:org.mitre.oval:def:842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0906" published="2004-06-01" name="CVE-2003-0906" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/547028" source="CERT-VN" patch="1" adv="1">VU#547028</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://www.securityfocus.com/bid/10120" source="BID">10120</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:959" source="OVAL" sig="1">oval:org.mitre.oval:def:959</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:897" source="OVAL" sig="1">oval:org.mitre.oval:def:897</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1064" source="OVAL" sig="1">oval:org.mitre.oval:def:1064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0907" published="2004-06-01" name="CVE-2003-0907" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/260588" source="CERT-VN" patch="1" adv="1">VU#260588</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108196864221676&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040413 [Full-Disclosure] iDEFENSE Security Advisory 04.13.04 - Microsoft Help and Support</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020065.html" source="FULLDISC">20040413 Microsoft Help and Support Center argument injection vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15704" source="XF">win-hcpurl-code-execution(15704)</ref>
      <ref url="http://www.securityfocus.com/bid/10119" source="BID">10119</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=100&amp;type=vulnerabilities" source="MISC">http://www.idefense.com/application/poi/display?id=100&amp;type=vulnerabilities</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:904" source="OVAL" sig="1">oval:org.mitre.oval:def:904</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1000" source="OVAL" sig="1">oval:org.mitre.oval:def:1000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0908" published="2004-06-01" name="CVE-2003-0908" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/526084" source="CERT-VN" patch="1" adv="1">VU#526084</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/general/04-0001.html" source="MISC" patch="1" adv="1">http://www.appsecinc.com/resources/alerts/general/04-0001.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0082.html" source="VULNWATCH">20040414 [SHATTER Team Security Alert] Microsoft Windows Utility Manager Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15632" source="XF">win2k-utilitymgr-gain-privileges(15632)</ref>
      <ref url="http://www.securityfocus.com/bid/10124" source="BID">10124</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html" source="MISC">http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1046" source="OVAL" sig="1">oval:org.mitre.oval:def:1046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0909" published="2004-06-01" name="CVE-2003-0909" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/206468" source="CERT-VN" patch="1" adv="1">VU#206468</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15678" source="XF">winxp-task-gain-privileges(15678)</ref>
      <ref url="http://www.securityfocus.com/bid/10125" source="BID">10125</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1004" source="OVAL" sig="1">oval:org.mitre.oval:def:1004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0910" published="2004-06-01" name="CVE-2003-0910" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/122076" source="CERT-VN" patch="1" adv="1">VU#122076</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413D.html" source="EEYE" patch="1" adv="1">AD20040413D</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html" source="FULLDISC">20040413 EEYE: Windows Expand-Down Data Segment Local Privilege Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15707" source="XF">win-ldt-gain-privileges(15707)</ref>
      <ref url="http://www.securityfocus.com/bid/10122" source="BID">10122</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:911" source="OVAL" sig="1">oval:org.mitre.oval:def:911</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:890" source="OVAL" sig="1">oval:org.mitre.oval:def:890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0913" published="2003-12-01" name="CVE-2003-0913" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8979" source="BID" patch="1" adv="1">8979</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13620" source="XF">macos-terminal-gain-access(13620)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00040.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00040.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=120269" source="CONFIRM" adv="1">http://docs.info.apple.com/article.html?artnum=120269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0914" published="2003-12-15" name="CVE-2003-0914" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/734644" source="CERT-VN" patch="1" adv="1">VU#734644</ref>
      <ref url="http://www.debian.org/security/2004/dsa-409" source="DEBIAN" patch="1" adv="1">DSA-409</ref>
      <ref url="http://www.trustix.org/errata/misc/2003/TSL-2003-0044-bind.asc.txt" source="TRUSTIX">2003-0044</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57434" source="SUNALERT">57434</ref>
      <ref url="http://secunia.com/advisories/10542" source="SECUNIA">10542</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.33/CSSA-2003-SCO.33.txt" source="SCO">CSSA-2003-SCO.33</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-003.0/CSSA-2004-003.0.txt" source="SCO">CSSA-2004-003.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2011" source="OVAL" sig="1">oval:org.mitre.oval:def:2011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.3.0" />
        <vers num="8.3.1" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.4" />
        <vers num="8.4.1" />
      </prod>
      <prod vendor="nixu" name="namesurfer">
        <vers num="standard_3.0.1" />
        <vers num="suite_3.0.1" />
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0f" />
        <vers num="4.0f_pk6_bl17" />
        <vers num="4.0f_pk7_bl18" />
        <vers num="4.0f_pk8_bl22" />
        <vers num="4.0g" />
        <vers num="4.0g_pk3_bl17" />
        <vers num="4.0g_pk4_bl22" />
        <vers num="5.1" />
        <vers num="5.1_pk3_bl17" />
        <vers num="5.1_pk4_bl18" />
        <vers num="5.1_pk5_bl19" />
        <vers num="5.1_pk6_bl20" />
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1a_pk4_bl21" />
        <vers num="5.1a_pk5_bl23" />
        <vers num="5.1b" />
        <vers num="5.1b_pk1_bl1" />
        <vers num="5.1b_pk2_bl22" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.6.2" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="5.1l" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="current" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0924" published="2004-02-17" name="CVE-2003-0924" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/487102" source="CERT-VN" adv="1">VU#487102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-030.html" source="REDHAT" patch="1" adv="1">RHSA-2004:030</ref>
      <ref url="http://www.debian.org/security/2004/dsa-426" source="DEBIAN" patch="1" adv="1">DSA-426</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14874" source="XF" adv="1">netpbm-temp-insecure-file(14874)</ref>
      <ref url="http://www.securityfocus.com/bid/9442" source="BID" adv="1">9442</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-031.html" source="REDHAT">RHSA-2004:031</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:011" source="MANDRAKE">MDKSA-2004:011</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-02.xml" source="GENTOO">GLSA-200410-02</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:810" source="OVAL" sig="1">oval:org.mitre.oval:def:810</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:804" source="OVAL" sig="1">oval:org.mitre.oval:def:804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netpbm" name="netpbm">
        <vers prev="1" num="9.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0925" published="2003-12-01" name="CVE-2003-0925" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8951" source="BID" patch="1" adv="1">8951</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-323.html" source="REDHAT" patch="1" adv="1">RHSA-2003:323</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00011.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00011.html</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-64.txt" source="TURBO">TLSA-2003-64</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-324.html" source="REDHAT">RHSA-2003:324</ref>
      <ref url="http://www.debian.org/security/2003/dsa-407" source="DEBIAN">DSA-407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9692" source="OVAL">oval:org.mitre.oval:def:9692</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114" source="MANDRAKE">MDKSA-2003:114</ref>
      <ref url="http://secunia.com/advisories/10531" source="SECUNIA">10531</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780" source="CONECTIVA">CLA-2003:780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0926" published="2003-12-01" name="CVE-2003-0926" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8951" source="BID" patch="1" adv="1">8951</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-324.html" source="REDHAT" patch="1" adv="1">RHSA-2003:324</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00011.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00011.html</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-64.txt" source="TURBO">TLSA-2003-64</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-323.html" source="REDHAT">RHSA-2003:323</ref>
      <ref url="http://www.debian.org/security/2003/dsa-407" source="DEBIAN">DSA-407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11648" source="OVAL">oval:org.mitre.oval:def:11648</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780" source="CONECTIVA">CLA-2003:780</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114" source="MANDRAKE">MDKSA-2003:114</ref>
      <ref url="http://secunia.com/advisories/10531" source="SECUNIA">10531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0927" published="2003-12-01" name="CVE-2003-0927" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8951" source="BID" patch="1" adv="1">8951</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-323.html" source="REDHAT" patch="1" adv="1">RHSA-2003:323</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00011.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00011.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13578" source="XF">ethereal-socks-heap-overflow(13578)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-64.txt" source="TURBO">TLSA-2003-64</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-324.html" source="REDHAT">RHSA-2003:324</ref>
      <ref url="http://www.debian.org/security/2003/dsa-407" source="DEBIAN">DSA-407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9691" source="OVAL">oval:org.mitre.oval:def:9691</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780" source="CONECTIVA">CLA-2003:780</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114" source="MANDRAKE">MDKSA-2003:114</ref>
      <ref url="http://secunia.com/advisories/10531" source="SECUNIA">10531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0928" published="2004-09-28" name="CVE-2003-0928" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.corsaire.com/advisories/c030807-001.txt" source="MISC">http://www.corsaire.com/advisories/c030807-001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109241692108678&amp;w=2" source="BUGTRAQ">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers prev="1" num="4.3.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0929" published="2004-09-28" name="CVE-2003-0929" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.corsaire.com/advisories/c030807-001.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c030807-001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109241692108678&amp;w=2" source="BUGTRAQ">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers prev="1" num="4.3.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0930" published="2004-09-28" name="CVE-2003-0930" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.corsaire.com/advisories/c030807-001.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c030807-001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109241692108678&amp;w=2" source="BUGTRAQ">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers prev="1" num="4.3.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0931" published="2004-09-28" name="CVE-2003-0931" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.corsaire.com/advisories/c031120-001.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c031120-001.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16949" source="XF" adv="1">sygate-enforcer-payload-dos(16949)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215951022437&amp;w=2" source="BUGTRAQ">20040810 Corsaire Security Advisory - Sygate Enforcer discovery packet DoS issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sygate_technologies" name="enforcer">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0932" published="2003-12-15" name="CVE-2003-0932" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-400" source="DEBIAN" patch="1" adv="1">DSA-400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omega-rpg" name="omega-rpg">
        <vers num="0.9.0_pa9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0933" published="2003-12-01" name="CVE-2003-0933" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-398" source="DEBIAN" patch="1" adv="1">DSA-398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conquest" name="conquest">
        <vers num="7.1.1_-6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0934" published="2003-12-01" name="CVE-2003-0934" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.secnap.net/security/031106.html" source="MISC" patch="1" adv="1">http://www.secnap.net/security/031106.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106850011513880&amp;w=2" source="BUGTRAQ">20031110 Symbol Technologies Default WEP KEYS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symbol_technologies" name="pdt">
        <vers num="8100" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0935" published="2003-12-01" name="CVE-2003-0935" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-335.html" source="REDHAT" patch="1" adv="1">RHSA-2003:335</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=308015" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=308015</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-023.html" source="REDHAT">RHSA-2004:023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9802" source="OVAL">oval:org.mitre.oval:def:9802</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000778" source="CONECTIVA">CLA-2003:778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:869" source="OVAL" sig="1">oval:org.mitre.oval:def:869</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net-snmp" name="net-snmp">
        <vers num="5.0.1" />
        <vers num="5.0.3" />
        <vers num="5.0.4_pre2" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0936" published="2003-12-15" name="CVE-2003-0936" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2003.11.13.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2003.11.13.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106876107330752&amp;w=2" source="BUGTRAQ">20031113 RE: Secure Network Operations SRT2003-11-13-0218, PCAnywhere allows local users to become SYSTEM</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106875764826251&amp;w=2" source="BUGTRAQ">20031113 SRT2003-11-13-0218 - PCAnywhere local SYSTEM exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="10.0" />
        <vers num="10.5" />
        <vers num="11.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0937" published="2003-12-15" name="CVE-2003-0937" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.texonet.com/advisories/TEXONET-20031024.txt" source="MISC" patch="1" adv="1">http://www.texonet.com/advisories/TEXONET-20031024.txt</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.32/CSSA-2003-SCO.32.txt" source="SCO" patch="1" adv="1">CSSA-2003-SCO.32</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106865297403687&amp;w=2" source="BUGTRAQ">20031112 Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_unix">
        <vers num="8.0" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
        <vers num="7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0938" published="2003-12-15" name="CVE-2003-0938" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-1.txt" source="ATSTAKE" patch="1" adv="1">A111703-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13765" source="XF" adv="1">sapdb-NETAPI32-gain-privileges(13765)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0939" published="2003-12-15" name="CVE-2003-0939" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256 byte segment to the niserver (aka serv.exe) process on TCP port 7269, which prevents the server from NULL terminating the string and leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-1.txt" source="ATSTAKE" patch="1" adv="1">A111703-1</ref>
      <ref url="http://www.sapdb.org/7.4/new_relinfo.txt" source="CONFIRM">http://www.sapdb.org/7.4/new_relinfo.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0940" published="2003-12-15" name="CVE-2003-0940" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" source="ATSTAKE" patch="1" adv="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0941" published="2003-12-15" name="CVE-2003-0941" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" source="ATSTAKE" patch="1" adv="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0942" published="2003-12-15" name="CVE-2003-0942" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin.wa.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" source="ATSTAKE" patch="1" adv="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0943" published="2003-12-15" name="CVE-2003-0943" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redirect attacks against internal databases via (1) waecho, (2) Web SQL Interface (websql), or (3) Web Database Manager (webdbm).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" source="ATSTAKE" patch="1" adv="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0944" published="2003-12-15" name="CVE-2003-0944" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL with a long requestURI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" source="ATSTAKE" patch="1" adv="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0945" published="2003-12-15" name="CVE-2003-0945" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13774" source="XF" adv="1">sapdb-manager-sessionid-predictable(13774)</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" source="ATSTAKE" adv="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers prev="1" num="7.4.03.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0946" published="2003-12-15" name="CVE-2003-0946" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=197038" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=197038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106867135830683&amp;w=2" source="BUGTRAQ">20031112 SRT2003-11-11-1151 - clamav-milter remote exploit / DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.60" />
        <vers num="0.60p" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0947" published="2003-12-15" name="CVE-2003-0947" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106867458902521&amp;w=2" source="BUGTRAQ" adv="1">20031112 iwconfig vulnerability - the last code was demaged sending by email</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0948" published="2003-12-15" name="CVE-2003-0948" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8901" source="BID" adv="1">8901</ref>
      <ref url="http://www.securiteam.com/exploits/6Y00R1P8KY.html" source="MISC" adv="1">http://www.securiteam.com/exploits/6Y00R1P8KY.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireless_tools" name="wireless_tools">
        <vers num="19" />
        <vers num="20" />
        <vers num="21" />
        <vers num="22" />
        <vers num="23" />
        <vers num="24" />
        <vers num="25" />
        <vers num="26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0949" published="2004-02-03" name="CVE-2003-0949" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9321" source="BID" patch="1" adv="1">9321</ref>
      <ref url="http://www.debian.org/security/2003/dsa-405" source="DEBIAN" patch="1" adv="1">DSA-405</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14098" source="XF" adv="1">xsok-command-execution(14098)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_bischoff" name="xsok">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0950" published="2003-12-15" name="CVE-2003-0950" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12805" source="XF" adv="1">peoplesoft-iclientservlet-file-upload(12805)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/157" source="ISS">20031112 IClient Servlet Remote Command Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/9041" source="BID" adv="1">9041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.10" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="8.15" />
        <vers num="8.16" />
        <vers num="8.17" />
        <vers num="8.18" />
        <vers num="8.19" />
        <vers num="8.20" />
        <vers num="8.4" />
        <vers num="8.40" />
        <vers num="8.41" />
        <vers num="8.42" />
        <vers num="8.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0951" published="2003-12-15" name="CVE-2003-0951" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q4/0041.html" source="HP" patch="1" adv="1">HPSBUX0311-296</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5146" source="OVAL">oval:org.mitre.oval:def:5146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0954" published="2003-12-31" name="CVE-2003-0954" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9078" source="BID" patch="1">9078</ref>
      <ref url="http://secunia.com/advisories/10276/" source="SECUNIA" patch="1">10276</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY49238&amp;apar=only" source="AIXAPAR">IY49238</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY48747&amp;apar=only" source="AIXAPAR">IY48747</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY48272&amp;apar=only" source="AIXAPAR">IY48272</ref>
      <ref url="http://securitytracker.com/id?1008258" source="SECTRACK">1008258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0955" published="2003-12-15" name="CVE-2003-0955" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=106917441524978&amp;w=2" source="CONFIRM" patch="1" adv="1">http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=106917441524978&amp;w=2</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch" source="OPENBSD" patch="1">20031105 005: RELIABILITY FIX: November 4, 2003</ref>
      <ref url="http://www.securityfocus.com/bid/8978" source="BID">8978</ref>
      <ref url="http://www.openbsd.org/errata33.html" source="OPENBSD">20031104 010: RELIABILITY FIX: November 4, 2003</ref>
      <ref url="http://www.guninski.com/msuxobsd2.html" source="MISC" adv="1">http://www.guninski.com/msuxobsd2.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013315.html" source="FULLDISC">20031104 OpenBSD kernel overflow, yet still *BSD much better than windows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=106808820119679&amp;w=2" source="CONFIRM">http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=106808820119679&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0956" published="2003-12-31" name="CVE-2003-0956" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cause incorrect data to be returned when a file is truncated as it is being read, which might allow local users to obtain sensitive data that was originally owned by other users, a different vulnerability than CVE-2003-0018.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Linux O_DIRECT versions 2.4.22 and previous</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42942" source="XF">linux-kernel-odirect-information-disclosure(42942)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0959" published="2003-12-31" name="CVE-2003-0959" modified="2009-04-08" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows attackers to cause a denial of service or gain root privileges via unspecified vectors that trigger copy_from_user function calls with improper length arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/43072" source="XF">linux-kernel-unspecified-priv-escalation(43072)</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@3ed382f7UfJ9Q2LKCJq1Tc5B7-EC5A" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@3ed382f7UfJ9Q2LKCJq1Tc5B7-EC5A</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0960" published="2003-12-15" name="CVE-2003-0960" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107003609308765&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031128 [OpenCA Advisory] Vulnerabilities in signature verification</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openca" name="openca">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.6" />
        <vers num="0.9.0" />
        <vers num="0.9.0.1" />
        <vers num="0.9.0.2" />
        <vers num="0.9.1" />
        <vers num="0.9.1.2" />
        <vers num="0.9.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0961" published="2003-12-15" name="CVE-2003-0961" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/301156" source="CERT-VN">VU#301156</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-389.html" source="REDHAT" patch="1" adv="1">RHSA-2003:389</ref>
      <ref url="http://www.debian.org/security/2003/dsa-403" source="DEBIAN" patch="1" adv="1">DSA-403</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-368.html" source="REDHAT">RHSA-2003:368</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_049_kernel.html" source="SUSE">SuSE-SA:2003:049</ref>
      <ref url="http://www.debian.org/security/2004/dsa-475" source="DEBIAN">DSA-475</ref>
      <ref url="http://www.debian.org/security/2004/dsa-470" source="DEBIAN">DSA-470</ref>
      <ref url="http://www.debian.org/security/2004/dsa-450" source="DEBIAN">DSA-450</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2004/dsa-440" source="DEBIAN">DSA-440</ref>
      <ref url="http://www.debian.org/security/2004/dsa-439" source="DEBIAN">DSA-439</ref>
      <ref url="http://www.debian.org/security/2004/dsa-433" source="DEBIAN">DSA-433</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-417" source="DEBIAN">DSA-417</ref>
      <ref url="http://secunia.com/advisories/10338" source="SECUNIA">10338</ref>
      <ref url="http://secunia.com/advisories/10333" source="SECUNIA">10333</ref>
      <ref url="http://secunia.com/advisories/10330" source="SECUNIA">10330</ref>
      <ref url="http://secunia.com/advisories/10329" source="SECUNIA">10329</ref>
      <ref url="http://secunia.com/advisories/10328" source="SECUNIA">10328</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107064798706473&amp;w=2" source="BUGTRAQ" adv="1">20031204 [iSEC] Linux kernel do_brk() vulnerability details</ref>
      <ref url="http://isec.pl/papers/linux_kernel_do_brk.pdf" source="MISC">http://isec.pl/papers/linux_kernel_do_brk.pdf</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:110" source="MANDRAKE">MDKSA-2003:110</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394143105081&amp;w=2" source="BUGTRAQ">20040112 SmoothWall Project Security Advisory SWP-2004:001</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107064830206816&amp;w=2" source="BUGTRAQ">20031204 Hot fix for do_brk bug</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000796" source="CONECTIVA">CLA-2003:796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0962" published="2003-12-15" name="CVE-2003-0962" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/325603" source="CERT-VN">VU#325603</ref>
      <ref url="http://www.securityfocus.com/bid/9153" source="BID" patch="1" adv="1">9153</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-398.html" source="REDHAT" patch="1" adv="1">RHSA-2003:398</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107055681311602&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031204 rsync security advisory (fwd)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13899" source="XF" adv="1">linux-rsync-heap-overflow(13899)</ref>
      <ref url="http://www.osvdb.org/2898" source="OSVDB">2898</ref>
      <ref url="http://secunia.com/advisories/10474" source="SECUNIA">10474</ref>
      <ref url="http://secunia.com/advisories/10378" source="SECUNIA">10378</ref>
      <ref url="http://secunia.com/advisories/10364" source="SECUNIA">10364</ref>
      <ref url="http://secunia.com/advisories/10363" source="SECUNIA">10363</ref>
      <ref url="http://secunia.com/advisories/10362" source="SECUNIA">10362</ref>
      <ref url="http://secunia.com/advisories/10361" source="SECUNIA">10361</ref>
      <ref url="http://secunia.com/advisories/10360" source="SECUNIA">10360</ref>
      <ref url="http://secunia.com/advisories/10359" source="SECUNIA">10359</ref>
      <ref url="http://secunia.com/advisories/10358" source="SECUNIA">10358</ref>
      <ref url="http://secunia.com/advisories/10357" source="SECUNIA">10357</ref>
      <ref url="http://secunia.com/advisories/10356" source="SECUNIA">10356</ref>
      <ref url="http://secunia.com/advisories/10355" source="SECUNIA">10355</ref>
      <ref url="http://secunia.com/advisories/10354" source="SECUNIA">10354</ref>
      <ref url="http://secunia.com/advisories/10353" source="SECUNIA">10353</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9415" source="OVAL">oval:org.mitre.oval:def:9415</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107056923528423&amp;w=2" source="BUGTRAQ">20031204 GLSA: exploitable heap overflow in rsync (200312-03)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107055702911867&amp;w=2" source="BUGTRAQ">20031204 [OpenPKG-SA-2003.051] OpenPKG Security Advisory (rsync)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107055684711629&amp;w=2" source="TRUSTIX">2003-0048</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000794" source="CONECTIVA">CLA-2003:794</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U" source="SGI">20031202-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:111" source="MANDRAKE">MDKSA-2003:111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_tridgell" name="rsync">
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.8" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
      </prod>
      <prod vendor="redhat" name="rsync">
        <vers num="2.4.6-2" edition="" />
        <vers num="2.4.6-2" edition=":i386" />
        <vers num="2.4.6-5" edition="" />
        <vers num="2.4.6-5" edition=":ia64" />
        <vers num="2.4.6-5" edition=":i386" />
        <vers num="2.5.4-2" edition="" />
        <vers num="2.5.4-2" edition=":i386" />
        <vers num="2.5.5-1" edition="" />
        <vers num="2.5.5-1" edition=":i386" />
        <vers num="2.5.5-4" edition="" />
        <vers num="2.5.5-4" edition=":i386" />
      </prod>
      <prod vendor="engardelinux" name="secure_community">
        <vers num="1.0.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="engardelinux" name="secure_linux">
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":professional" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":professional" />
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":professional" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="8.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="current" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0963" published="2004-01-05" name="CVE-2003-0963" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107152267121513&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031213 lftp buffer overflows</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-404.html" source="REDHAT">RHSA-2003:404</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_051_lftp.html" source="SUSE">SuSE-SA:2003:051</ref>
      <ref url="http://www.debian.org/security/2004/dsa-406" source="DEBIAN">DSA-406</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11180" source="OVAL">oval:org.mitre.oval:def:11180</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U" source="SGI">20040101-01-U</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-403.html" source="REDHAT">RHSA-2003:403</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:116" source="MANDRAKE">MDKSA-2003:116</ref>
      <ref url="http://secunia.com/advisories/10548" source="SECUNIA">10548</ref>
      <ref url="http://secunia.com/advisories/10525" source="SECUNIA">10525</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340499504411&amp;w=2" source="CONECTIVA">CLA-2004:800</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107177409418121&amp;w=2" source="BUGTRAQ">20031218 GLSA: lftp (200312-07)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107167974714484&amp;w=2" source="BUGTRAQ">20031217 [OpenPKG-SA-2003.053] OpenPKG Security Advisory (lftp)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107126386226196&amp;w=2" source="BUGTRAQ">20031212 [slackware-security]  lftp security update (SSA:2003-346-01)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_v._lukyanov" name="lftp">
        <vers num="2.3" />
        <vers num="2.4.9" />
        <vers num="2.5.2" />
        <vers num="2.6.0" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0964" reject="1" published="2003-11-17" name="CVE-2003-0964" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: N/A. Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0965" published="2004-02-17" name="CVE-2003-0965" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-020.html" source="REDHAT" patch="1" adv="1">RHSA-2004:020</ref>
      <ref url="http://mail.python.org/pipermail/mailman-announce/2003-December/000066.html" source="MLIST" patch="1" adv="1">[Mailman-Announce] 20031231 RELEASED Mailman 2.1.4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14121" source="XF" adv="1">mailman-admin-xss(14121)</ref>
      <ref url="http://www.securityfocus.com/bid/9336" source="BID" adv="1">9336</ref>
      <ref url="http://www.debian.org/security/2004/dsa-436" source="DEBIAN">DSA-436</ref>
      <ref url="http://www.osvdb.org/3305" source="OSVDB">3305</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:013" source="MANDRAKE">MDKSA-2004:013</ref>
      <ref url="http://secunia.com/advisories/10519" source="SECUNIA">10519</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" source="CONECTIVA">CLA-2004:842</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:813" source="OVAL" sig="1">oval:org.mitre.oval:def:813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers prev="1" num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0966" published="2004-02-17" name="CVE-2003-0966" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the frm command in elm 2.5.6 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code via a long Subject line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9430" source="BID" patch="1" adv="1">9430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-009.html" source="REDHAT" patch="1" adv="1">RHSA-2004:009</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=112078" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=112078</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14840" source="XF">elm-frm-subject-bo(14840)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elm_development_group" name="elm">
        <vers prev="1" num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0967" published="2003-12-15" name="CVE-2003-0967" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-386.html" source="REDHAT">RHSA-2003:386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10917" source="OVAL">oval:org.mitre.oval:def:10917</ref>
      <ref url="http://marc.theaimsgroup.com/?l=freeradius-users&amp;m=106947389449613&amp;w=2" source="CONFIRM" adv="1">http://marc.theaimsgroup.com/?l=freeradius-users&amp;m=106947389449613&amp;w=2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106944220426970" source="BUGTRAQ" adv="1">20031121 FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106935911101493&amp;w=2" source="BUGTRAQ" adv="1">20031120 Remote DoS in FreeRADIUS, all versions.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers prev="1" num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0968" published="2003-12-15" name="CVE-2003-0968" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106986437621130&amp;w=2" source="BUGTRAQ" adv="1">20031126 FreeRADIUS &lt;= 0.9.3 rlm_smb module stack overflow vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0969" published="2004-01-20" name="CVE-2003-0969" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14148" source="XF" adv="1">mpg321-mp3-format-string(14148)</ref>
      <ref url="http://www.securityfocus.com/bid/9364" source="BID" adv="1">9364</ref>
      <ref url="http://www.osvdb.org/3331" source="OSVDB">3331</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_02_tcpdump.html" source="SUSE">SuSE-SA:2004:002</ref>
      <ref url="http://www.debian.org/security/2004/dsa-411" source="DEBIAN">DSA-411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg321" name="mpg321">
        <vers num="0.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0970" published="2003-12-15" name="CVE-2003-0970" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57430" source="SUNALERT" patch="1" adv="1">57430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sun_fire">
        <vers num="b1600" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0971" published="2003-12-15" name="CVE-2003-0971" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/940388" source="CERT-VN">VU#940388</ref>
      <ref url="http://www.securityfocus.com/bid/9115" source="BID" patch="1" adv="1">9115</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106995769213221&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031127 GnuPG's ElGamal signing keys compromised</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.html" source="CONFIRM" patch="1">http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.html</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.html" source="CONFIRM" patch="1" adv="1">http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-395.html" source="REDHAT">RHSA-2003:395</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-390.html" source="REDHAT">RHSA-2003:390</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_048_gpg.html" source="SUSE">SuSE-SA:2003:048</ref>
      <ref url="http://www.debian.org/security/2004/dsa-429" source="DEBIAN">DSA-429</ref>
      <ref url="http://secunia.com/advisories/10400" source="SECUNIA">10400</ref>
      <ref url="http://secunia.com/advisories/10399" source="SECUNIA">10399</ref>
      <ref url="http://secunia.com/advisories/10349" source="SECUNIA">10349</ref>
      <ref url="http://secunia.com/advisories/10304" source="SECUNIA">10304</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10982" source="OVAL">oval:org.mitre.oval:def:10982</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:109" source="MANDRAKE">MDKSA-2003:109</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000798" source="CONECTIVA">CLA-2003:798</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3b" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0972" published="2003-12-15" name="CVE-2003-0972" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-408" source="DEBIAN" patch="1" adv="1">DSA-408</ref>
      <ref url="http://groups.yahoo.com/group/gnu-screen/message/3118" source="CONFIRM">http://groups.yahoo.com/group/gnu-screen/message/3118</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:113" source="MANDRAKE">MDKSA-2003:113</ref>
      <ref url="http://secunia.com/advisories/10539" source="SECUNIA">10539</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106995837813873&amp;w=2" source="BUGTRAQ">20031127 GNU screen buffer overflow</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000809" source="CONECTIVA">CLA-2004:809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="screen">
        <vers num="3.9.10" />
        <vers num="3.9.11" />
        <vers num="3.9.13" />
        <vers num="3.9.15" />
        <vers num="3.9.4" />
        <vers num="3.9.8" />
        <vers num="3.9.9" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0973" published="2003-12-15" name="CVE-2003-0973" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-058.html" source="REDHAT" patch="1" adv="1">RHSA-2004:058</ref>
      <ref url="http://www.modpython.org/pipermail/mod_python/2003-November/004005.html" source="CONFIRM" patch="1">http://www.modpython.org/pipermail/mod_python/2003-November/004005.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-452" source="DEBIAN" patch="1" adv="1">DSA-452</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-063.html" source="REDHAT">RHSA-2004:063</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10259" source="OVAL">oval:org.mitre.oval:def:10259</ref>
      <ref url="http://bugzilla.fedora.us/show_bug.cgi?id=1325" source="FEDORA">FEDORA-2004-1325</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000837" source="CONECTIVA">CLA-2004:837</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:839" source="OVAL" sig="1">oval:org.mitre.oval:def:839</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:828" source="OVAL" sig="1">oval:org.mitre.oval:def:828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_python">
        <vers num="2.7" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.3" />
        <vers num="2.7.4" />
        <vers num="2.7.5" />
        <vers num="2.7.6" />
        <vers num="2.7.7" />
        <vers num="2.7.8" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0974" published="2003-12-15" name="CVE-2003-0974" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using addrule.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9124" source="BID" patch="1" adv="1">9124</ref>
      <ref url="http://www.bugtraq.org/advisories/_BSSADV-0000.txt" source="MISC">http://www.bugtraq.org/advisories/_BSSADV-0000.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107005523025918&amp;w=2" source="BUGTRAQ" adv="1">20031128 Applied Watch Response to Bugtraq.org post - Was: Multiple Remote Issues in Applied Watch IDS Suite</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107004362416252&amp;w=2" source="BUGTRAQ" adv="1">20031128 Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107031196324376&amp;w=2" source="BUGTRAQ">20031201 Re: Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="applied_watch_technologies" name="applied_watch_command_center">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0975" published="2003-12-15" name="CVE-2003-0975" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/7973" source="XF">mozilla-netscape-steal-cookies(7973)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106917674428552&amp;w=2" source="BUGTRAQ" adv="1">20031118 Apple Safari 1.1 (v100)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00042.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00042.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0976" published="2003-12-15" name="CVE-2003-0976" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10089375.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10089375.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13915" source="XF">netware-nfs-share-access(13915)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0977" published="2004-01-05" name="CVE-2003-0977" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-422" source="DEBIAN" patch="1" adv="1">DSA-422</ref>
      <ref url="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&amp;JServSessionIdservlets=8u3x1myav1" source="CONFIRM" patch="1">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&amp;JServSessionIdservlets=8u3x1myav1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13929" source="XF" adv="1">cvs-module-file-manipulation(13929)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-004.html" source="REDHAT">RHSA-2004:004</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-003.html" source="REDHAT">RHSA-2004:003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11528" source="OVAL">oval:org.mitre.oval:def:11528</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:112" source="MANDRAKE">MDKSA-2003:112</ref>
      <ref url="http://secunia.com/advisories/10601" source="SECUNIA">10601</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107540163908129&amp;w=2" source="BUGTRAQ">20040129 [FLSA-2004:1207] Updated cvs resolves security vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107168035515554&amp;w=2" source="BUGTRAQ">20031217 [OpenPKG-SA-2003.052] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000808" source="CONECTIVA">CLA-2004:808</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:866" source="OVAL" sig="1">oval:org.mitre.oval:def:866</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:855" source="OVAL" sig="1">oval:org.mitre.oval:def:855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="8.1" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0978" published="2004-01-05" name="CVE-2003-0978" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13892" source="XF" adv="1">gnupg-gpgkeyshkp-format-string(13892)</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20031203.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20031203.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_048_gpg.html" source="SUSE">SuSE-SA:2003:048</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107047470625214&amp;w=2" source="BUGTRAQ" adv="1">20031203 GnuPG 1.2.3, 1.3.3 external HKP interface format string issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.3" />
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0979" published="2004-01-05" name="CVE-2003-0979" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" source="MISC" patch="1" adv="1">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107107840622493&amp;w=2" source="BUGTRAQ">20031210 Visitorbook LE Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freescripts" name="visitorbook">
        <vers num="le" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0980" published="2004-01-05" name="CVE-2003-0980" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE (visitorbook.pl) allows remote attackers to inject arbitrary HTML or web script via (1) the "do" parameter, (2) via the "user" parameter from a host with a malicious reverse DNS name, (3) via quote marks or ampersands in other parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" source="MISC" patch="1" adv="1">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107107840622493&amp;w=2" source="BUGTRAQ">20031210 Visitorbook LE Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freescripts" name="visitorbook">
        <vers num="le" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0981" published="2004-01-05" name="CVE-2003-0981" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" source="MISC" patch="1" adv="1">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107107840622493&amp;w=2" source="BUGTRAQ">20031210 Visitorbook LE Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freescripts" name="visitorbook">
        <vers num="le" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0982" published="2004-01-05" name="CVE-2003-0982" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/352462" source="CERT-VN">VU#352462</ref>
      <ref url="http://www.securityfocus.com/bid/9187" source="BID" patch="1" adv="1">9187</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml" source="CISCO" patch="1" adv="1">20031210 Vulnerability in Authentication Library for ACNS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13945" source="XF">cisco-acns-password-bo(13945)</ref>
      <ref url="http://secunia.com/advisories/10409" source="SECUNIA">10409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="4.0.3" />
        <vers num="4.1.1" />
        <vers num="4.1.3" />
        <vers num="4.2" />
        <vers num="4.2.7" />
        <vers num="4.2.9" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.3" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4630">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4650">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="content_distribution_manager_4670">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_engine">
        <vers num="507" />
        <vers num="507_2.2_.0" />
        <vers num="507_3.1" />
        <vers num="507_4.0" />
        <vers num="507_4.1" />
        <vers num="560" />
        <vers num="560_2.2_.0" />
        <vers num="560_3.1" />
        <vers num="560_4.0" />
        <vers num="560_4.1" />
        <vers num="590" />
        <vers num="590_2.2_.0" />
        <vers num="590_3.1" />
        <vers num="590_4.0" />
        <vers num="590_4.1" />
        <vers num="7320" />
        <vers num="7320_2.2_.0" />
        <vers num="7320_3.1" />
        <vers num="7320_4.0" />
        <vers num="7320_4.1" />
      </prod>
      <prod vendor="cisco" name="content_engine_module">
        <vers num="for_cisco_router_2600_series" />
        <vers num="for_cisco_router_3600_series" />
        <vers num="for_cisco_router_3700_series" />
      </prod>
      <prod vendor="cisco" name="content_router_4430">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_router_4450">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_router_4430">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0983" published="2004-01-05" name="CVE-2003-0983" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20031210-unity.shtml" source="CISCO" patch="1" adv="1">20031210 Unity Vulnerabilities on IBM-based Servers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="80-7111-01_for_the_unity-svrx255-1a">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="80-7112-01_for_the_unity-svrx255-2a">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0984" published="2004-01-05" name="CVE-2003-0984" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT" patch="1" adv="1">RHSA-2004:188</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13943" source="XF" adv="1">linux-rtc-memory-leak(13943)</ref>
      <ref url="http://www.securityfocus.com/bid/9154" source="BID" adv="1">9154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-417.html" source="REDHAT">RHSA-2003:417</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_049_kernel.html" source="SUSE">SuSE-SA:2003:049</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html" source="ENGARDE">ESA-20040105-001</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9406" source="OVAL">oval:org.mitre.oval:def:9406</ref>
      <ref url="http://www.securitytracker.com/id?1008594" source="SECTRACK">1008594</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00000.html" source="FEDORA">FEDORA-2003-046</ref>
      <ref url="http://www.osvdb.org/3317" source="OSVDB">3317</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:001" source="MANDRAKE">MDKSA-2004:001</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/10583" source="SECUNIA">10583</ref>
      <ref url="http://secunia.com/advisories/10582" source="SECUNIA">10582</ref>
      <ref url="http://secunia.com/advisories/10555" source="SECUNIA">10555</ref>
      <ref url="http://secunia.com/advisories/10538" source="SECUNIA">10538</ref>
      <ref url="http://secunia.com/advisories/10537" source="SECUNIA">10537</ref>
      <ref url="http://secunia.com/advisories/10536" source="SECUNIA">10536</ref>
      <ref url="http://secunia.com/advisories/10533" source="SECUNIA">10533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394143105081&amp;w=2" source="BUGTRAQ">20040112 SmoothWall Project Security Advisory SWP-2004:001</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000799" source="CONECTIVA">CLA-2004:799</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:859" source="OVAL" sig="1">oval:org.mitre.oval:def:859</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1013" source="OVAL" sig="1">oval:org.mitre.oval:def:1013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0985" published="2004-01-20" name="CVE-2003-0985" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/490620" source="CERT-VN">VU#490620</ref>
      <ref url="http://www.securityfocus.com/bid/9356" source="BID" patch="1" adv="1">9356</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-417.html" source="REDHAT" patch="1" adv="1">RHSA-2003:417</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html" source="ENGARDE" patch="1" adv="1">ESA-20040105-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14135" source="XF" adv="1">linux-domremap-gain-privileges(14135)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-419.html" source="REDHAT">RHSA-2003:419</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-418.html" source="REDHAT">RHSA-2003:418</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-416.html" source="REDHAT">RHSA-2003:416</ref>
      <ref url="http://www.osvdb.org/3315" source="OSVDB">3315</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_03_linux_kernel.html" source="SUSE">SuSE-SA:2004:003</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:001" source="MANDRAKE">MDKSA-2004:001</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.debian.org/security/2004/dsa-475" source="DEBIAN">DSA-475</ref>
      <ref url="http://www.debian.org/security/2004/dsa-470" source="DEBIAN">DSA-470</ref>
      <ref url="http://www.debian.org/security/2004/dsa-450" source="DEBIAN">DSA-450</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2004/dsa-440" source="DEBIAN">DSA-440</ref>
      <ref url="http://www.debian.org/security/2004/dsa-439" source="DEBIAN">DSA-439</ref>
      <ref url="http://www.debian.org/security/2004/dsa-427" source="DEBIAN">DSA-427</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-417" source="DEBIAN">DSA-417</ref>
      <ref url="http://www.debian.org/security/2004/dsa-413" source="DEBIAN">DSA-413</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-045.shtml" source="CIAC">O-045</ref>
      <ref url="http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2005-0528?op=file&amp;rev=0&amp;sc=0" source="CONFIRM">http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2005-0528?op=file&amp;rev=0&amp;sc=0</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/10532" source="SECUNIA">10532</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394143105081&amp;w=2" source="BUGTRAQ">20040112 SmoothWall Project Security Advisory SWP-2004:001</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350348418373&amp;w=2" source="BUGTRAQ">20040107 [slackware-security]  Kernel security update  (SSA:2004-006-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340814409017&amp;w=2" source="BUGTRAQ">20040106 Linux mremap bug correction</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358402129&amp;w=2" source="BUGTRAQ">20040105 Linux kernel do_mremap() proof-of-concept exploit code</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332782121916&amp;w=2" source="BUGTRAQ" adv="1">20040105 Linux kernel mremap vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332754521495&amp;w=2" source="TRUSTIX">2004-0001</ref>
      <ref url="http://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremap" source="CONFIRM">http://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremap</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0013-mremap.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0013-mremap.txt</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.3/updates/IMNX-2004-73-001-01" source="IMMUNIX">IMNX-2004-73-001-01</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000799" source="CONECTIVA">CLA-2004:799</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0070.html" source="BUGTRAQ">20040108 [slackware-security] Slackware 8.1 kernel security update (SSA:2004-008-01)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040102-01-U" source="SGI">20040102-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:867" source="OVAL" sig="1">oval:org.mitre.oval:def:867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:860" source="OVAL" sig="1">oval:org.mitre.oval:def:860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0986" published="2003-12-31" name="CVE-2003-0986" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-017.html" source="REDHAT" patch="1" adv="1">RHSA-2004:017</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@3ffcf122S7e3xPZCpibrXq6KRRjwqw" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.6/cset@3ffcf122S7e3xPZCpibrXq6KRRjwqw</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@3fdd54b3u9Eq0Wny2Nn1HGfI3pofOQ" source="CONFIRM" patch="1" adv="1">http://linux.bkbits.net:8080/linux-2.4/cset@3fdd54b3u9Eq0Wny2Nn1HGfI3pofOQ</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9707" source="OVAL">oval:org.mitre.oval:def:9707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0987" published="2004-03-03" name="CVE-2003-0987" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15041" source="XF" patch="1" adv="1">apache-moddigest-response-replay(15041)</ref>
      <ref url="http://www.securityfocus.com/bid/9571" source="BID" patch="1" adv="1">9571</ref>
      <ref url="http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html" source="CONFIRM" patch="1">http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://www.trustix.org/errata/2004/0027" source="TRUSTIX">2004-0027</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-600.html" source="REDHAT">RHSA-2004:600</ref>
      <ref url="http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html" source="CONFIRM" adv="1">http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-22.xml" source="GENTOO">GLSA-200405-22</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" source="SLACKWARE">SSA:2004-133</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046" source="MANDRAKE">MDKSA-2004:046</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" source="SUNALERT">101841</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://securitytracker.com/id?1008920" source="SECTRACK">1008920</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4416" source="OVAL" sig="1">oval:org.mitre.oval:def:4416</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100108" source="OVAL" sig="1">oval:org.mitre.oval:def:100108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="1.3.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0988" published="2004-02-17" name="CVE-2003-0988" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/820798" source="CERT-VN">VU#820798</ref>
      <ref url="http://www.securityfocus.com/bid/9419" source="BID" patch="1" adv="1">9419</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-005.html" source="REDHAT" patch="1" adv="1">RHSA-2004:005</ref>
      <ref url="http://www.kde.org/info/security/advisory-20040114-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20040114-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412130407906&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040114 KDE Security Advisory: VCF file information reader vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14833" source="XF" adv="1">kde-kdepim-bo(14833)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-006.html" source="REDHAT">RHSA-2004:006</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:003" source="MANDRAKE">MDKSA-2004:003</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-02.xml" source="GENTOO">GLSA-200404-02</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000810" source="CONECTIVA">CLA-2004:810</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:865" source="OVAL" sig="1">oval:org.mitre.oval:def:865</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:858" source="OVAL" sig="1">oval:org.mitre.oval:def:858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0989" published="2004-02-17" name="CVE-2003-0989" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/738518" source="CERT-VN" adv="1">VU#738518</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-007.html" source="REDHAT" patch="1" adv="1">RHSA-2004:007</ref>
      <ref url="http://www.debian.org/security/2004/dsa-425" source="DEBIAN" patch="1" adv="1">DSA-425</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded" source="BUGTRAQ">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-008.html" source="REDHAT">RHSA-2004:008</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" source="MLIST">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" source="FEDORA">FEDORA-2004-092</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" source="FEDORA">FEDORA-2004-090</ref>
      <ref url="http://secunia.com/advisories/12179/" source="SECUNIA">12179</ref>
      <ref url="http://secunia.com/advisories/11032/" source="SECUNIA">11032</ref>
      <ref url="http://secunia.com/advisories/11022" source="SECUNIA">11022</ref>
      <ref url="http://secunia.com/advisories/10718" source="SECUNIA">10718</ref>
      <ref url="http://secunia.com/advisories/10668" source="SECUNIA">10668</ref>
      <ref url="http://secunia.com/advisories/10652" source="SECUNIA">10652</ref>
      <ref url="http://secunia.com/advisories/10644" source="SECUNIA">10644</ref>
      <ref url="http://secunia.com/advisories/10639" source="SECUNIA">10639</ref>
      <ref url="http://secunia.com/advisories/10637" source="SECUNIA">10637</ref>
      <ref url="http://secunia.com/advisories/10636" source="SECUNIA">10636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10599" source="OVAL">oval:org.mitre.oval:def:10599</ref>
      <ref url="http://lwn.net/Alerts/66805/" source="ENGARDE">ESA-20040119-002</ref>
      <ref url="http://lwn.net/Alerts/66445/" source="TRUSTIX">2004-0004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" source="SCO">SCOSA-2004.9</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" source="CALDERA">CSSA-2004-008.0</ref>
      <ref url="http://www.securitytracker.com/id?1008716" source="SECTRACK">1008716</ref>
      <ref url="http://www.securityfocus.com/bid/9507" source="BID">9507</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" source="FEDORA">FLSA:1222</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" source="MANDRAKE">MDKSA-2004:008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" source="BUGTRAQ">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:852" source="OVAL" sig="1">oval:org.mitre.oval:def:852</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:847" source="OVAL" sig="1">oval:org.mitre.oval:def:847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="tcpdump">
        <vers prev="1" num="3.8.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0990" published="2004-01-20" name="CVE-2003-0990" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107247236124180&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031224 Bugtraq Security Systems ADV-0001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14079" source="XF" adv="1">squirrelmail-parseaddress-command-execution(14079)</ref>
      <ref url="http://www.securityfocus.com/bid/9296" source="BID" adv="1">9296</ref>
      <ref url="http://www.securityfocus.com/archive/1/348366" source="BUGTRAQ" adv="1">20031226 Re: Reported Command Injection in Squirrelmail GPG</ref>
      <ref url="http://www.bugtraq.org/advisories/_BSSADV-0001.txt" source="MISC">http://www.bugtraq.org/advisories/_BSSADV-0001.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0991" published="2004-03-03" name="CVE-2003-0991" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15106" source="XF" patch="1" adv="1">mailman-command-handler-dos(15106)</ref>
      <ref url="http://www.securityfocus.com/bid/9620" source="BID" patch="1" adv="1">9620</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-019.html" source="REDHAT" patch="1" adv="1">RHSA-2004:019</ref>
      <ref url="http://www.debian.org/security/2004/dsa-436" source="DEBIAN" patch="1" adv="1">DSA-436</ref>
      <ref url="http://mail.python.org/pipermail/mailman-announce/2004-February/000067.html" source="MLIST" patch="1" adv="1">[Mailman-Announce] 20040208 RELEASED: Mailman 2.0.14 patch-only release</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:013" source="MANDRAKE">MDKSA-2004:013</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" source="CONECTIVA">CLA-2004:842</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" edition="beta3" />
        <vers num="2.0" edition="beta4" />
        <vers num="2.0" edition="beta5" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0992" published="2004-02-17" name="CVE-2003-0992" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-020.html" source="REDHAT" patch="1" adv="1">RHSA-2004:020</ref>
      <ref url="http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html" source="CONFIRM" patch="1" adv="1">http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:013" source="MANDRAKE">MDKSA-2004:013</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" source="CONECTIVA">CLA-2004:842</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:815" source="OVAL" sig="1">oval:org.mitre.oval:def:815</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers prev="1" num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0993" published="2004-03-29" name="CVE-2003-0993" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9829" source="BID" patch="1" adv="1">9829</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15422" source="XF" adv="1">apache-modaccess-obtain-information(15422)</ref>
      <ref url="http://www.apacheweek.com/features/security-13" source="CONFIRM" adv="1">http://www.apacheweek.com/features/security-13</ref>
      <ref url="http://www.trustix.org/errata/2004/0027" source="TRUSTIX">2004-0027</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" source="SLACKWARE">SSA:2004-133</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" source="SUNALERT">101841</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-22.xml" source="GENTOO">GLSA-200405-22</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" source="BUGTRAQ">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869603013722" source="MLIST">[apache-cvs] 20040307 cvs commit: apache-1.3/src/modules/standard mod_access.c</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=23850" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=23850</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046" source="MANDRAKE">MDKSA-2004:046</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4670" source="OVAL" sig="1">oval:org.mitre.oval:def:4670</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100111" source="OVAL" sig="1">oval:org.mitre.oval:def:100111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.14" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.6" />
        <vers num="1.3.7" edition="" />
        <vers num="1.3.7" edition=":dev" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0994" published="2004-02-03" name="CVE-2003-0994" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107393473928245&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 Re:   SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</ref>
      <ref url="http://www.secnetops.biz/research/SRT2004-01-09-1022.txt" source="MISC">http://www.secnetops.biz/research/SRT2004-01-09-1022.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015510.html" source="BUGTRAQ">20040112 SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</ref>
      <ref url="http://www.osvdb.org/3428" source="OSVDB">3428</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015510.html" source="FULLDISC">20040112 SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ms_exchange" />
        <vers num="2001" edition="" />
        <vers num="2001" edition=":pro" />
        <vers num="2002" edition="" />
        <vers num="2002" edition=":pro" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":pro" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":pro" />
        <vers num="v3.0" edition="" />
        <vers num="v3.0" edition=":handhelds" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2001" edition="" />
        <vers num="2001" edition=":pro" />
        <vers num="2002" edition="" />
        <vers num="2002" edition=":pro" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":pro" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":pro" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
      <prod vendor="symantec" name="windows_liveupdate">
        <vers num="1.70.x" />
        <vers num="1.90.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0995" published="2004-01-05" name="CVE-2003-0995" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13131" source="XF" patch="1" adv="1">win2k-message-queue-bo(13131)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-039.asp" source="MS" patch="1" adv="1">MS03-039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0996" published="2004-01-05" name="CVE-2003-0996" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown "System Security Vulnerability" in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to gain privileges via the help interface.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.secunia.com/advisories/10420/" source="SECUNIA" patch="1" adv="1">10420</ref>
      <ref url="http://support.ca.com/techbases/rp/urc6x-secnote.html" source="CONFIRM" patch="1" adv="1">http://support.ca.com/techbases/rp/urc6x-secnote.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="unicenter_remote_control_host">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0997" published="2004-01-05" name="CVE-2003-0997" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown "Denial of Service Attack" vulnerability in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to cause a denial of service (CPU consumption in URC host service).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.secunia.com/advisories/10420/" source="SECUNIA" patch="1" adv="1">10420</ref>
      <ref url="http://support.ca.com/techbases/rp/urc6x-secnote.html" source="CONFIRM" patch="1" adv="1">http://support.ca.com/techbases/rp/urc6x-secnote.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="unicenter_remote_control_host">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0998" published="2004-01-05" name="CVE-2003-0998" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown "potential system security vulnerability" in Computer Associates (CA) Unicenter Remote Control 5.0 through 5.2, and ControlIT 5.0 and 5.1, may allow attackers to gain privileges to the local system account.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.secunia.com/advisories/10420/" source="SECUNIA" patch="1" adv="1">10420</ref>
      <ref url="http://support.ca.com/techbases/rp/urc5x-secnote.html" source="CONFIRM" patch="1" adv="1">http://support.ca.com/techbases/rp/urc5x-secnote.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="controlit">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":enterprise" />
        <vers num="5.0" edition=":advanced" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise" />
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="5.2" />
        <vers num="6.0" />
      </prod>
      <prod vendor="ca" name="unicenter_remote_control_option">
        <vers num="5.0" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":" />
        <vers num="5.1" edition="::de" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0999" published="2004-01-05" name="CVE-2003-0999" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57451" source="SUNALERT" patch="1" adv="1">57451</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4098" source="OVAL" sig="1">oval:org.mitre.oval:def:4098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1000" published="2004-01-05" name="CVE-2003-1000" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html" source="CONFIRM" patch="1" adv="1">http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107152093419276&amp;w=2" source="BUGTRAQ">20031214 GLSA: Malformed dcc send requests in xchat-2.0.6 lead to a denial of service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xchat" name="xchat">
        <vers num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1001" published="2004-01-05" name="CVE-2003-1001" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml" source="CISCO" patch="1" adv="1">20031215 Cisco FWSM Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-svc-nam-1">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-svc-nam-2">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-x6380-nam">
        <vers num="2.1(2)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-svc-nam-1">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-svc-nam-2">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-x6380-nam">
        <vers num="2.1(2)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2" />
      </prod>
      <prod vendor="cisco" name="catos">
        <vers num="5.4(1)" />
        <vers num="7.5(1)" />
        <vers num="7.6(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1002" published="2004-01-05" name="CVE-2003-1002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml" source="CISCO" patch="1" adv="1">20031215 Cisco FWSM Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-svc-nam-1">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-svc-nam-2">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-x6380-nam">
        <vers num="2.1(2)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-svc-nam-1">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-svc-nam-2">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-x6380-nam">
        <vers num="2.1(2)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2" />
      </prod>
      <prod vendor="cisco" name="catos">
        <vers num="5.4(1)" />
        <vers num="7.5(1)" />
        <vers num="7.6(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1003" published="2004-01-05" name="CVE-2003-1003" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtml" source="CISCO" patch="1" adv="1">20031215 Cisco PIX Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.1(4)" />
        <vers num="5.1(4.206)" />
        <vers num="5.2" />
        <vers num="5.2(1)" />
        <vers num="5.2(2)" />
        <vers num="5.2(3.210)" />
        <vers num="5.2(5)" />
        <vers num="5.2(6)" />
        <vers num="5.2(7)" />
        <vers num="5.2(9)" />
        <vers num="5.3" />
        <vers num="5.3(1)" />
        <vers num="5.3(1.200)" />
        <vers num="5.3(2)" />
        <vers num="5.3(3)" />
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.0(3)" />
        <vers num="6.0(4)" />
        <vers num="6.0(4.101)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(2)" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1(5)" />
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3.100)" />
        <vers num="6.3" />
        <vers num="6.3(1)" />
        <vers num="6.3(3.102)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1004" published="2004-01-05" name="CVE-2003-1004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtml" source="CISCO" patch="1" adv="1">20031215 Cisco PIX Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3.100)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1005" published="2003-12-31" name="CVE-2003-1005" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.auscert.org.au/render.html?it=3704" source="AUSCERT" patch="1">ESB-2003.0867</ref>
      <ref url="http://secunia.com/advisories/10474/" source="SECUNIA" patch="1">10474</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Dec/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2003-12-19</ref>
      <ref url="http://www.securityfocus.com/bid/9266" source="BID">9266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1006" published="2004-03-29" name="CVE-2003-1006" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/878526" source="CERT-VN" adv="1">VU#878526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13995" source="XF" patch="1" adv="1">macos-cd9660-bo(13995)</ref>
      <ref url="http://www.securityfocus.com/bid/9228" source="BID" patch="1" adv="1">9228</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/archive/1/348097" source="BUGTRAQ">20031219 Re: Buffer overflow/privilege escalation in MacOS X - hfs.util also</ref>
      <ref url="http://www.securityfocus.com/archive/1/347707" source="BUGTRAQ">20031216 Re: Buffer overflow/privilege escalation in MacOS X</ref>
      <ref url="http://www.securityfocus.com/archive/1/347578" source="BUGTRAQ" adv="1">20031215 Buffer overflow/privilege escalation in MacOS X</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1007" published="2004-03-29" name="CVE-2003-1007" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14051" source="XF" patch="1" adv="1">applefileserver-dos(14051)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/bid/9264" source="BID" adv="1">9264</ref>
      <ref url="http://securitytracker.com/id?1008532" source="SECTRACK">1008532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1008" published="2004-03-29" name="CVE-2003-1008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14195" source="XF" patch="1" adv="1">macos-screen-saver-bypass(14195)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1009" published="2004-03-29" name="CVE-2003-1009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13874" source="XF" patch="1" adv="1">macos-dhcp-gain-privileges(13874)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/bid/9110" source="BID" adv="1">9110</ref>
      <ref url="http://www.carrel.org/dhcp-vuln.html" source="MISC">http://www.carrel.org/dhcp-vuln.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=32478" source="MISC">http://docs.info.apple.com/article.html?artnum=32478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1010" published="2004-03-29" name="CVE-2003-1010" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in fs_usage in Mac OS X 10.2.8 and 10.3.2 and Mac OS X Server 10.2.8 and 10.3.2 allows local users to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14193" source="XF" patch="1" adv="1">macos-fsusage-gain-privileges(14193)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/bid/9265" source="BID" adv="1">9265</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1011" published="2004-03-29" name="CVE-2003-1011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13573" source="XF" patch="1" adv="1">macos-ctrlc-gain-access(13573)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/bid/8945" source="BID" adv="1">8945</ref>
      <ref url="http://www.securityfocus.com/archive/1/343087" source="BUGTRAQ" adv="1">20031031 Console Root On OSX up to 10.2.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1012" published="2004-01-05" name="CVE-2003-1012" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-001.html" source="REDHAT" patch="1" adv="1">RHSA-2004:001</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00012.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00012.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-407" source="DEBIAN" patch="1" adv="1">DSA-407</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-002.html" source="REDHAT">RHSA-2004:002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10202" source="OVAL">oval:org.mitre.oval:def:10202</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:002" source="MANDRAKE">MDKSA-2004:002</ref>
      <ref url="http://secunia.com/advisories/10570" source="SECUNIA">10570</ref>
      <ref url="http://secunia.com/advisories/10568" source="SECUNIA">10568</ref>
      <ref url="http://secunia.com/advisories/10531" source="SECUNIA">10531</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000801" source="CONECTIVA">CLA-2004:801</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:856" source="OVAL" sig="1">oval:org.mitre.oval:def:856</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1013" published="2004-01-05" name="CVE-2003-1013" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-001.html" source="REDHAT" patch="1" adv="1">RHSA-2004:001</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00012.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00012.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-002.html" source="REDHAT">RHSA-2004:002</ref>
      <ref url="http://www.debian.org/security/2003/dsa-407" source="DEBIAN">DSA-407</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10097" source="OVAL">oval:org.mitre.oval:def:10097</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:002" source="MANDRAKE">MDKSA-2004:002</ref>
      <ref url="http://secunia.com/advisories/10570" source="SECUNIA">10570</ref>
      <ref url="http://secunia.com/advisories/10568" source="SECUNIA">10568</ref>
      <ref url="http://secunia.com/advisories/10531" source="SECUNIA">10531</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000801" source="CONECTIVA">CLA-2004:801</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:857" source="OVAL" sig="1">oval:org.mitre.oval:def:857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1014" published="2004-10-20" name="CVE-2003-1014" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use multiple MIME fields with the same name, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17333" source="XF">mime-field-filtering-bypass(17333)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517732328759&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME field multiple occurrence issue</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1015" published="2004-10-20" name="CVE-2003-1015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/9273" source="XF">mime-tools-incorrect-concatenation(9273)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109525252118936&amp;w=2" source="BUGTRAQ">20040914 Corsaire Security Advisory - Multiple vendor MIME field whitespace issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1016" published="2004-10-20" name="CVE-2003-1016" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17336" source="XF">mime-quote-filtering-bypass(17336)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109521027007616&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME field quoting issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1017" published="2004-01-05" name="CVE-2003-1017" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read restricted files via vulnerabilities in web browsers whose exploits rely on predictable names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8900" source="BID" patch="1" adv="1">8900</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14013" source="XF">flash-file-predictable-location(14013)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="director">
        <vers num="5.0" />
      </prod>
      <prod vendor="macromedia" name="flash_player">
        <vers num="4.0_r12" />
        <vers num="5.0" />
        <vers num="5.0_r50" />
        <vers num="6.0" />
        <vers num="6.0.29.0" />
        <vers num="6.0.40.0" />
        <vers num="6.0.47.0" />
        <vers num="6.0.65.0" />
        <vers num="6.0.79.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1018" published="2004-03-29" name="CVE-2003-1018" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14037" source="XF" patch="1" adv="1">aix-enq-format-string(14037)</ref>
      <ref url="http://www.securityfocus.com/bid/9254" source="BID" patch="1" adv="1">9254</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-20" source="IBM">MSS-OAR-E01-20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1020" published="2004-01-05" name="CVE-2003-1020" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The format_send_to_gui function in formats.c for irssi before 0.8.9 allows remote IRC users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13973" source="XF" adv="1">irssi-dos(13973)</ref>
      <ref url="http://www.securityfocus.com/archive/1/347218" source="BUGTRAQ" adv="1">20031211 irssi - potential remote crash</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:117" source="MANDRAKE">MDKSA-2003:117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irssi" name="irssi">
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1021" published="2005-01-26" name="CVE-2003-1021" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/972598" source="CERT-VN" patch="1" adv="1">VU#972598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19479" source="XF" patch="1" adv="1">openserver-scosession-gain-privilege(19479)</ref>
      <ref url="http://secunia.com/advisories/14012/" source="SECUNIA" patch="1" adv="1">14012</ref>
      <ref url="http://www.securityfocus.com/bid/12372" source="BID" adv="1">12372</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.5/SCOSA-2005.5.txt" source="SCO">SCOSA-2005.5</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1022" published="2004-01-20" name="CVE-2003-1022" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9377" source="BID" patch="1" adv="1">9377</ref>
      <ref url="http://www.debian.org/security/2004/dsa-416" source="DEBIAN" patch="1" adv="1">DSA-416</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-048.shtml" source="CIAC" patch="1" adv="1">O-048</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14154" source="XF" adv="1">fspsuite-dot-directory-traversal(14154)</ref>
      <ref url="http://www.osvdb.org/3346" source="OSVDB">3346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="fsp">
        <vers prev="1" num="2.81.b18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1023" published="2004-01-20" name="CVE-2003-1023" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118433222764&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040405 [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13247" source="XF" adv="1">midnight-commander-vfssresolvesymlink-bo(13247)</ref>
      <ref url="http://www.securityfocus.com/bid/8658" source="BID" adv="1">8658</ref>
      <ref url="http://www.debian.org/security/2004/dsa-424" source="DEBIAN">DSA-424</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-09.xml" source="GENTOO" adv="1">GLSA-200403-09</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-035.html" source="REDHAT">RHSA-2004:035</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-034.html" source="REDHAT">RHSA-2004:034</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2004-May/msg00002.html" source="FEDORA">FLSA:1224</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:007" source="MANDRAKE">MDKSA-2004:007</ref>
      <ref url="http://secunia.com/advisories/9833" source="SECUNIA">9833</ref>
      <ref url="http://secunia.com/advisories/11296" source="SECUNIA">11296</ref>
      <ref url="http://secunia.com/advisories/11268" source="SECUNIA">11268</ref>
      <ref url="http://secunia.com/advisories/11262" source="SECUNIA">11262</ref>
      <ref url="http://secunia.com/advisories/11219" source="SECUNIA">11219</ref>
      <ref url="http://secunia.com/advisories/10823" source="SECUNIA">10823</ref>
      <ref url="http://secunia.com/advisories/10772" source="SECUNIA">10772</ref>
      <ref url="http://secunia.com/advisories/10716" source="SECUNIA">10716</ref>
      <ref url="http://secunia.com/advisories/10685" source="SECUNIA">10685</ref>
      <ref url="http://secunia.com/advisories/10645" source="SECUNIA">10645</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-058.shtml" source="FEDORA">FEDORA-2004-058</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000833" source="CONECTIVA">CLA-2004:833</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2003/09/msg00309.html" source="BUGTRAQ">20030919 uninitialized buffer in midnight commander</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt" source="CALDERA">CSSA-2004-014.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:822" source="OVAL" sig="1">oval:org.mitre.oval:def:822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.52" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1024" published="2004-01-20" name="CVE-2003-1024" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/281356" source="CERT-VN">VU#281356</ref>
      <ref url="http://www.securityfocus.com/bid/9280" source="BID" patch="1" adv="1">9280</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57455" source="SUNALERT" patch="1" adv="1">57455</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14065" source="XF">solaris-lsf-gain-privileges(14065)</ref>
      <ref url="http://secunia.com/advisories/10486" source="SECUNIA">10486</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1528" source="OVAL" sig="1">oval:org.mitre.oval:def:1528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1025" published="2004-01-20" name="CVE-2003-1025" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-033A.html" source="CERT">TA04-033A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/652278" source="CERT-VN" adv="1">VU#652278</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13935" source="XF" adv="1">ie-domain-url-spoofing(13935)</ref>
      <ref url="http://www.zapthedingbat.com/security/ex01/vun1.htm" source="MISC" adv="1">http://www.zapthedingbat.com/security/ex01/vun1.htm</ref>
      <ref url="http://www.securityfocus.com/archive/1/346948" source="BUGTRAQ" adv="1">20031209 Internet Explorer URL parsing vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-004.asp" source="MS">MS04-004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:526" source="OVAL" sig="1">oval:org.mitre.oval:def:526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:513" source="OVAL" sig="1">oval:org.mitre.oval:def:513</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:512" source="OVAL" sig="1">oval:org.mitre.oval:def:512</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:511" source="OVAL" sig="1">oval:org.mitre.oval:def:511</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:510" source="OVAL" sig="1">oval:org.mitre.oval:def:510</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:491" source="OVAL" sig="1">oval:org.mitre.oval:def:491</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:490" source="OVAL" sig="1">oval:org.mitre.oval:def:490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1026" published="2004-01-20" name="CVE-2003-1026" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-033A.html" source="CERT">TA04-033A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/784102" source="CERT-VN" adv="1">VU#784102</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106979349517578&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031125 BackToFramedJpu - a successor of BackToJpu attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13846" source="XF" adv="1">ie-subframe-xss(13846)</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-004.asp" source="MS">MS04-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107038202225587&amp;w=2" source="BUGTRAQ" adv="1">20031201 Comments on 5 IE vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:805" source="OVAL" sig="1">oval:org.mitre.oval:def:805</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:774" source="OVAL" sig="1">oval:org.mitre.oval:def:774</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:745" source="OVAL" sig="1">oval:org.mitre.oval:def:745</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:689" source="OVAL" sig="1">oval:org.mitre.oval:def:689</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:687" source="OVAL" sig="1">oval:org.mitre.oval:def:687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:643" source="OVAL" sig="1">oval:org.mitre.oval:def:643</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:630" source="OVAL" sig="1">oval:org.mitre.oval:def:630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1027" published="2004-01-20" name="CVE-2003-1027" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-033A.html" source="CERT">TA04-033A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/413886" source="CERT-VN" adv="1">VU#413886</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106979479719446&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031125 HijackClickV2 - a successor of HijackClick attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13844" source="XF" adv="1">ie-method-perform-actions(13844)</ref>
      <ref url="http://www.securitytracker.com/id?1006036" source="SECTRACK">1006036</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-004.asp" source="MS">MS04-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107038202225587&amp;w=2" source="BUGTRAQ" adv="1">20031201 Comments on 5 IE vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:629" source="OVAL" sig="1">oval:org.mitre.oval:def:629</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:534" source="OVAL" sig="1">oval:org.mitre.oval:def:534</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:532" source="OVAL" sig="1">oval:org.mitre.oval:def:532</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:531" source="OVAL" sig="1">oval:org.mitre.oval:def:531</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:530" source="OVAL" sig="1">oval:org.mitre.oval:def:530</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:529" source="OVAL" sig="1">oval:org.mitre.oval:def:529</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:527" source="OVAL" sig="1">oval:org.mitre.oval:def:527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1028" published="2004-01-20" name="CVE-2003-1028" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106979624321665&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031125 Invalid ContentType may disclose cache directory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13847" source="XF" adv="1">ie-download-directory-disclosure(13847)</ref>
      <ref url="http://www.safecenter.net/UMBRELLAWEBV4/threadid10008" source="MISC">http://www.safecenter.net/UMBRELLAWEBV4/threadid10008</ref>
      <ref url="http://www.osvdb.org/7890" source="OSVDB">7890</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107038202225587&amp;w=2" source="BUGTRAQ">20031201 Comments on 5 IE vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106979428718705&amp;w=2" source="BUGTRAQ">20031125 Note for "Invalid ContentType may disclose cache directory"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1029" published="2004-02-17" name="CVE-2003-1029" modified="2009-02-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-425" source="DEBIAN" patch="1" adv="1">DSA-425</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded" source="BUGTRAQ">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
      <ref url="http://secunia.com/advisories/10718" source="SECUNIA">10718</ref>
      <ref url="http://secunia.com/advisories/10668" source="SECUNIA">10668</ref>
      <ref url="http://secunia.com/advisories/10652" source="SECUNIA">10652</ref>
      <ref url="http://secunia.com/advisories/10636" source="SECUNIA">10636</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107213553214985&amp;w=2" source="BUGTRAQ" adv="1">20031221 Re: Remote crash in tcpdump from OpenBSD</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107193841728533&amp;w=2" source="BUGTRAQ" adv="1">20031220 Remote crash in tcpdump from OpenBSD</ref>
      <ref url="http://lwn.net/Alerts/66805/" source="ENGARDE">ESA-20040119-002</ref>
      <ref url="http://www.securitytracker.com/id?1008748" source="SECTRACK">1008748</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" source="MANDRAKE">MDKSA-2004:008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107228187124962&amp;w=2" source="MLIST">[tcpdump-workers] 20031224 Seg fault of tcpdump (v 3.8.1 and below) with malformed l2tp packets</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.2" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1030" published="2004-02-17" name="CVE-2003-1030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/909678" source="CERT-VN" adv="1">VU#909678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14001" source="XF" patch="1" adv="1">dameware-spoof-packet-bo(14001)</ref>
      <ref url="http://www.securityfocus.com/bid/9213" source="BID" patch="1" adv="1">9213</ref>
      <ref url="http://sh0dan.org/files/dwmrcs372.txt" source="MISC">http://sh0dan.org/files/dwmrcs372.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107152094119279&amp;w=2" source="BUGTRAQ" adv="1">20031214 DameWare Mini Remote Control Server &lt;= 3.72 Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392603615840&amp;w=2" source="BUGTRAQ">20040110 DameWare Mini Remote Control &lt; v3.73 remote exploit by kralor]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107187110617266&amp;w=2" source="BUGTRAQ">20031219 [Exploit]: DameWare Mini Remote Control Server Overflow Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dameware_development" name="mini_remote_control_server">
        <vers num="3.70_.0.0" />
        <vers num="3.71_.0.0" />
        <vers num="3.72_.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1031" published="2004-02-17" name="CVE-2003-1031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0078.html" source="VULNWATCH" adv="1">20030808 VBulletin New Member XSS Vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1032" published="2004-02-17" name="CVE-2003-1032" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7787" source="BID" patch="1" adv="1">7787</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105484265218325&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030602 Tripbit Advisory TA-2003-05 Buffer Overflow Vulnerability in Pi3 Web</ref>
      <ref url="http://securitytracker.com/id?1006913" source="SECTRACK">1006913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105484265218325&amp;w=2" source="BUGTRAQ">20030605 Re: Tripbit Advisory TA-2003-05 Buffer Overflow Vulnerability in Pi3 Web</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pi3" name="pi3web">
        <vers num="2.0.2_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1033" published="2004-04-15" name="CVE-2003-1033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7407" source="BID" patch="1" adv="1">7407</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11842" source="XF" adv="1">sap-db-gain-privileges(11842)</ref>
      <ref url="http://www.securityfocus.com/bid/7408" source="BID">7408</ref>
      <ref url="http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html" source="MLIST">[SAP DB Dev] 20030422 Security Alert: Development Tools</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105103613727471&amp;w=2" source="BUGTRAQ">20030422 SRT2003-04-22-1336 - SAP DB Development Tools install flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers num="7.3.00" />
        <vers num="7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1034" published="2004-04-15" name="CVE-2003-1034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11669" source="XF" patch="1" adv="1">sap-db-world-writable(11669)</ref>
      <ref url="http://www.securityfocus.com/bid/7242" source="BID" patch="1" adv="1">7242</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914778303805&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030331 SRT2003-03-31-1219 - SAP world writable server binaries</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1035" published="2004-04-15" name="CVE-2003-1035" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11487" source="XF" adv="1">sap-sapinfo-lockout-bypass(11487)</ref>
      <ref url="http://www.securityfocus.com/bid/7007" source="BID" adv="1">7007</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004039.html" source="FULLDISC">20030304 SAP R/3, account locking and RFC SDK</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451378/100/0/threaded" source="BUGTRAQ">20061112 Old SAP exploits</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_r_3">
        <vers num="" />
      </prod>
      <prod vendor="sap" name="sapgui">
        <vers num="4.6c" edition="" />
        <vers num="4.6c" edition=":windows" />
        <vers num="4.6d" edition="" />
        <vers num="4.6d" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1036" published="2004-04-15" name="CVE-2003-1036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session parameters, or (4) a long HTTP Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14186" source="XF" adv="1">sap-multiple-bo(14186)</ref>
      <ref url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" source="MISC">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="internet_transaction_server">
        <vers prev="1" num="4.6_pl463" />
        <vers prev="1" num="6.10_pl30" />
        <vers prev="1" num="6.20_pl7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1037" published="2004-04-15" name="CVE-2003-1037" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15514" source="XF" patch="1" adv="1">sap-wgate-format-string(15514)</ref>
      <ref url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" source="MISC">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
      <ref url="http://securitytracker.com/id?1009453" source="SECTRACK">1009453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="internet_transaction_server">
        <vers prev="1" num="4.6_pl463" />
        <vers prev="1" num="6.10_pl30" />
        <vers prev="1" num="6.20_pl7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1038" published="2004-04-15" name="CVE-2003-1038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list of installed DLLs and full pathnames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15516" source="XF" patch="1" adv="1">sap-agate-path-disclosure(15516)</ref>
      <ref url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" source="MISC">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="internet_transaction_server">
        <vers prev="1" num="4.6_pl463" />
        <vers prev="1" num="6.10_pl30" />
        <vers prev="1" num="6.20_pl7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1039" published="2004-04-15" name="CVE-2003-1039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Application Server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15513" source="XF" adv="1">mysap-host-header-bo(15513)</ref>
      <ref url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd" source="MISC">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="mysap_business_suite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1040" published="2004-04-15" name="CVE-2003-1040" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15577" source="XF" patch="1" adv="1">linux-kmod-signals-dos(15577)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT">RHSA-2004:188</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-069.html" source="REDHAT">RHSA-2004:069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_049_kernel.html" source="SUSE">SuSE-SA:2003:049</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9423" source="OVAL">oval:org.mitre.oval:def:9423</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/diffs/kernel/kmod.c@1.6?nav=index.html%7Csrc/%7Csrc/kernel%7Chist/kernel/kmod.c" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/diffs/kernel/kmod.c@1.6?nav=index.html|src/|src/kernel|hist/kernel/kmod.c</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040204-01-U.asc" source="SGI">20040204-01-U</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" source="CONECTIVA">CLSA-2004:820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1041" published="2004-06-14" name="CVE-2003-1041" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/187196" source="CERT-VN">VU#187196</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14105" source="XF" adv="1">ie-showhelp-directory-traversal(14105)</ref>
      <ref url="http://www.securityfocus.com/bid/9320" source="BID" adv="1">9320</ref>
      <ref url="http://www.securityfocus.com/archive/1/348521" source="BUGTRAQ" adv="1">20031230 IE 5.x-6.0 allows executing arbitrary programs using showHelp()</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-023.asp" source="MS">MS04-023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:956" source="OVAL" sig="1">oval:org.mitre.oval:def:956</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3514" source="OVAL" sig="1">oval:org.mitre.oval:def:3514</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1943" source="OVAL" sig="1">oval:org.mitre.oval:def:1943</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1186" source="OVAL" sig="1">oval:org.mitre.oval:def:1186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6" edition="windows_server_2003_sp1" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1042" published="2004-08-18" name="CVE-2003-1042" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8953" source="BID" patch="1" adv="1">8953</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13594" source="XF" adv="1">bugzilla-productname-sql-injection(13594)</ref>
      <ref url="http://www.securityfocus.com/archive/1/343185" source="BUGTRAQ">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" source="CONECTIVA" adv="1">CLA-2003:774</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=214290" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=214290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1043" published="2004-08-18" name="CVE-2003-1043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8953" source="BID" patch="1" adv="1">8953</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13596" source="XF" adv="1">bugzilla-url-sql-injection(13596)</ref>
      <ref url="http://www.securityfocus.com/archive/1/343185" source="BUGTRAQ">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" source="CONECTIVA" adv="1">CLA-2003:774</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=219044" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=219044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1044" published="2004-08-18" name="CVE-2003-1044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8953" source="BID" patch="1" adv="1">8953</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13597" source="XF" adv="1">bugzilla-groupid-gain-privileges(13597)</ref>
      <ref url="http://www.securityfocus.com/archive/1/343185" source="BUGTRAQ">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=219690" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=219690</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" source="CONECTIVA">CLA-2003:774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1045" published="2004-08-18" name="CVE-2003-1045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8953" source="BID" patch="1" adv="1">8953</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=209376" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=209376</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13600" source="XF" adv="1">bugzilla-obtain-information(13600)</ref>
      <ref url="http://www.securityfocus.com/archive/1/343185" source="BUGTRAQ">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" source="CONECTIVA">CLA-2003:774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1046" published="2004-08-18" name="CVE-2003-1046" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8953" source="BID" patch="1" adv="1">8953</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13602" source="XF" adv="1">bugzilla-describecomponents-obtain-info(13602)</ref>
      <ref url="http://www.securityfocus.com/archive/1/343185" source="BUGTRAQ">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=209742" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=209742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-1047" reject="1" published="2004-08-06" name="CVE-2003-1047" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0540.  Reason: This candidate is a duplicate of CVE-2004-0540.  Notes: All CVE users should reference CVE-2004-0540 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-1048" published="2004-07-27" name="CVE-2003-1048" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-212A.html" source="CERT">TA04-212A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/685364" source="CERT-VN" adv="1">VU#685364</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16804" source="XF">ie-mshtml-gif-bo(16804)</ref>
      <ref url="http://www.securityfocus.com/bid/8530" source="BID" adv="1">8530</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx" source="MS">MS04-025</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-191.shtml" source="CIAC">O-191</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009506.html" source="FULLDISC">20040903 Re: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll Denial of Service?</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009473.html" source="FULLDISC">20040902 AW: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009445.html" source="FULLDISC">20030902 New Microsoft Internet Explorer mshtml.dll Denial of Service?</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:517" source="OVAL" sig="1">oval:org.mitre.oval:def:517</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:509" source="OVAL" sig="1">oval:org.mitre.oval:def:509</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:236" source="OVAL" sig="1">oval:org.mitre.oval:def:236</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:212" source="OVAL" sig="1">oval:org.mitre.oval:def:212</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2100" source="OVAL" sig="1">oval:org.mitre.oval:def:2100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:206" source="OVAL" sig="1">oval:org.mitre.oval:def:206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1793" source="OVAL" sig="1">oval:org.mitre.oval:def:1793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1049" published="2004-09-28" name="CVE-2003-1049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14030" source="XF" patch="1" adv="1">db2-dms-insecure-permissions(14030)</ref>
      <ref url="http://www.securityfocus.com/bid/9243" source="BID" patch="1" adv="1">9243</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY44842&amp;apar=only" source="AIXAPAR">IY44842</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY44841&amp;apar=only" source="AIXAPAR" adv="1">IY44841</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":linux" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1050" published="2004-09-28" name="CVE-2003-1050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13633" source="XF" patch="1" adv="1">db2-multiple-binaries-bo(13633)</ref>
      <ref url="http://www.securityfocus.com/bid/8990" source="BID" patch="1" adv="1">8990</ref>
      <ref url="http://www.securityfocus.com/archive/1/343804" source="BUGTRAQ" patch="1" adv="1">20031108 SRT2003-11-06-0710 - IBM DB2 Multiple local security issues</ref>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt" source="MISC">http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1051" published="2004-09-28" name="CVE-2003-1051" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13633" source="XF" patch="1" adv="1">db2-multiple-binaries-bo(13633)</ref>
      <ref url="http://www.securityfocus.com/bid/8989" source="BID" patch="1" adv="1">8989</ref>
      <ref url="http://www.securityfocus.com/archive/1/343804" source="BUGTRAQ" adv="1">20031108 SRT2003-11-06-0710 - IBM DB2 Multiple local security issues</ref>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt" source="MISC">http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1052" published="2004-09-28" name="CVE-2003-1052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8346" source="BID" patch="1" adv="1">8346</ref>
      <ref url="http://www.securityfocus.com/archive/1/331904" source="BUGTRAQ" patch="1" adv="1">20030805 Slight privilege elevation from bin to root in IBM DB2 7.1 - 8.1 all binaries</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12826" source="XF" adv="1">ibm-db2-gain-privileges(12826)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="9.0" />
      </prod>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="6.0" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":linux" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":linux" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":linux" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":aix" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1053" published="2003-10-03" name="CVE-2003-1053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8776" source="BID" patch="1" adv="1">8776</ref>
      <ref url="http://www.securityfocus.com/bid/8770" source="BID" patch="1" adv="1">8770</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=213957" source="CONFIRM" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=213957</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13359" source="XF" adv="1">xshisen-xshisenlib-bo(13359)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13358" source="XF" adv="1">xshisen-kconv-bo(13358)</ref>
      <ref url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref>
      <ref url="http://secunia.com/advisories/9950" source="SECUNIA" adv="1">9950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xshisen" name="xshisen">
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1054" published="2003-04-16" name="CVE-2003-1054" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7375" source="BID" patch="1" adv="1">7375</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=151905" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=151905</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004555.html" source="FULLDISC" patch="1" adv="1">20030416 [VulnWatch] Apache mod_access_referer denial of service issue</ref>
      <ref url="http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html</ref>
      <ref url="http://secunia.com/advisories/8612" source="SECUNIA" adv="1">8612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_access_referer" name="mod_access_referer">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1055" published="2003-07-03" name="CVE-2003-1055" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11641" source="XF" patch="1" adv="1">solaris-nssldapso1-bo(11641)</ref>
      <ref url="http://www.securityfocus.com/bid/7064" source="BID" patch="1" adv="1">7064</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-113.shtml" source="CIAC" patch="1" adv="1">N-113</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52222-1" source="SUNALERT" patch="1" adv="1">52222</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3224" source="AUSCERT" adv="1">ESB-2003.0461</ref>
      <ref url="http://www.securitytracker.com/id?1006401" source="SECTRACK">1006401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1056" published="2003-12-11" name="CVE-2003-1056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13952" source="XF" patch="1" adv="1">solaris-ed1-tmpfile-insecure(13952)</ref>
      <ref url="http://www.securityfocus.com/bid/9199" source="BID" patch="1" adv="1">9199</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3688" source="AUSCERT" patch="1" adv="1">ESB-2003.0851</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57443-1" source="SUNALERT" patch="1" adv="1">57443</ref>
      <ref url="http://secunia.com/advisories/10411" source="SECUNIA" patch="1" adv="1">10411</ref>
      <ref url="http://www.osvdb.org/2955" source="OSVDB" adv="1">2955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1057" published="2003-12-08" name="CVE-2003-1057" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13914" source="XF" patch="1" adv="1">cde-dtprintinfo-gain-privileges(13914)</ref>
      <ref url="http://www.osvdb.org/2924" source="OSVDB" patch="1" adv="1">2924</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-035.shtml" source="CIAC" patch="1" adv="1">O-035</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3675" source="AUSCERT" patch="1" adv="1">ESB-2003.0844</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57441-1" source="SUNALERT" patch="1" adv="1">57441</ref>
      <ref url="http://secunia.com/advisories/10384" source="SECUNIA" patch="1" adv="1">10384</ref>
      <ref url="http://www.securityfocus.com/bid/9170" source="BID">9170</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1058" published="2003-12-03" name="CVE-2003-1058" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13890" source="XF" patch="1" adv="1">solaris-xsun-gain-privileges(13890)</ref>
      <ref url="http://www.osvdb.org/2892" source="OSVDB" patch="1" adv="1">2892</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-033.shtml" source="CIAC" patch="1" adv="1">O-033</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57419-1" source="SUNALERT" patch="1" adv="1">57419</ref>
      <ref url="http://secunia.com/advisories/10346" source="SECUNIA" patch="1" adv="1">10346</ref>
      <ref url="http://www.securityfocus.com/bid/9147" source="BID">9147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1059" published="2003-11-20" name="CVE-2003-1059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9076" source="BID" patch="1" adv="1">9076</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-029.shtml" source="CIAC" patch="1" adv="1">O-029</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57360-1" source="SUNALERT" patch="1" adv="1">57360</ref>
      <ref url="http://secunia.com/advisories/10267" source="SECUNIA" patch="1" adv="1">10267</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13792" source="XF" adv="1">solaris-pgx32-gain-privileges(13792)</ref>
      <ref url="http://www.osvdb.org/2839" source="OSVDB" adv="1">2839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1060" published="2003-10-27" name="CVE-2003-1060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13547" source="XF" patch="1" adv="1">solaris-nfs-ufs-dos(13547)</ref>
      <ref url="http://www.securityfocus.com/bid/8929" source="BID" patch="1" adv="1">8929</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57406-1" source="SUNALERT" patch="1" adv="1">57406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1061" published="2003-10-14" name="CVE-2003-1061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13434" source="XF" patch="1" adv="1">solaris-race-dos(13434)</ref>
      <ref url="http://www.securityfocus.com/bid/8836" source="BID" patch="1" adv="1">8836</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57080-1" source="SUNALERT" patch="1" adv="1">57080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1062" published="2003-10-15" name="CVE-2003-1062" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13435" source="XF" patch="1" adv="1">solaris-sysinfo-read-memory(13435)</ref>
      <ref url="http://www.securityfocus.com/bid/8831" source="BID" patch="1" adv="1">8831</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57340-1" source="SUNALERT" patch="1" adv="1">57340</ref>
      <ref url="http://secunia.com/advisories/10006/" source="SECUNIA" patch="1" adv="1">10006</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1063" published="2003-08-20" name="CVE-2003-1063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12942" source="XF" patch="1" adv="1">solaris-cachefs-inetdconf-overwrite(12942)</ref>
      <ref url="http://www.securityfocus.com/bid/8461" source="BID" patch="1" adv="1">8461</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-134.shtml" source="CIAC" patch="1" adv="1">N-134</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56300-1" source="SUNALERT" patch="1" adv="1">56300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1064" published="2003-07-23" name="CVE-2003-1064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Solaris 8 with IPv6 enabled allows remote attackers to cause a denial of service (kernel panic) via a crafted IPv6 packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/370060" source="CERT-VN" patch="1" adv="1">VU#370060</ref>
      <ref url="http://www.securityfocus.com/bid/8250" source="BID" patch="1" adv="1">8250</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55301-1" source="SUNALERT" patch="1" adv="1">55301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12680" source="XF" adv="1">solaris-ipv6-packet-dos(12680)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1065" published="2003-07-23" name="CVE-2003-1065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow local users to cause a denial of service (automountd crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19441" source="XF" patch="1" adv="1">openssh-ldap-dos(19441)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19437" source="XF" patch="1" adv="1">automountd-dos(19437)</ref>
      <ref url="http://www.securityfocus.com/bid/8253" source="BID" patch="1" adv="1">8253</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55340-1" source="SUNALERT" patch="1" adv="1">55340</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1066" published="2003-12-31" name="CVE-2003-1066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7820" source="BID" patch="1">7820</ref>
      <ref url="http://secunia.com/advisories/8944/" source="SECUNIA" patch="1">8944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12194" source="XF">sun-syslogd-bo(12194)</ref>
      <ref url="http://www.securityfocus.com/archive/1/324015" source="BUGTRAQ">20030604 Solaris syslogd overflow</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55440-1" source="SUNALERT" adv="1">55440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1067" published="2003-06-19" name="CVE-2003-1067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12379" source="XF" patch="1" adv="1">sun-database-functions-bo(12379)</ref>
      <ref url="http://www.securityfocus.com/bid/7991" source="BID" patch="1" adv="1">7991</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-108.shtml" source="CIAC" patch="1" adv="1">N-108</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55420-1" source="SUNALERT" patch="1" adv="1">55420</ref>
      <ref url="http://secunia.com/advisories/9088/" source="SECUNIA" patch="1" adv="1">9088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1068" published="2003-06-06" name="CVE-2003-1068" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11083" source="XF" patch="1" adv="1">solaris-utmp-update-bo(11083)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55260-1" source="SUNALERT" patch="1" adv="1">55260</ref>
      <ref url="http://secunia.com/advisories/8957/" source="SECUNIA" patch="1" adv="1">8957</ref>
      <ref url="http://www.securityfocus.com/bid/7835" source="BID">7835</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-105.shtml" source="CIAC">N-105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1069" published="2003-06-03" name="CVE-2003-1069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7794" source="BID" patch="1">7794</ref>
      <ref url="http://secunia.com/advisories/8935/" source="SECUNIA" patch="1">8935</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12140" source="XF">sun-intelnetd-dos(12140)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54181-1" source="SUNALERT" adv="1">54181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1070" published="2003-04-28" name="CVE-2003-1070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11906" source="XF" patch="1" adv="1">sun-rpcbind-dos(11906)</ref>
      <ref url="http://www.securityfocus.com/bid/7455" source="BID" patch="1" adv="1">7455</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50922-1" source="SUNALERT" patch="1" adv="1">50922</ref>
      <ref url="http://secunia.com/advisories/8685/" source="SECUNIA" patch="1" adv="1">8685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1071" published="2003-01-03" name="CVE-2003-1071" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/944241" source="CERT-VN" adv="1">VU#944241</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11608" source="XF" patch="1" adv="1">solaris-wall-message-spoofing(11608)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51980-1" source="SUNALERT" patch="1" adv="1">51980</ref>
      <ref url="http://www.securityfocus.com/archive/1/305105" source="BUGTRAQ" adv="1">20030103 Solaris 2.x /usr/sbin/wall Advisory</ref>
      <ref url="http://secunia.com/advisories/7825/" source="SECUNIA" adv="1">7825</ref>
      <ref url="http://www.securitytracker.com/id?1006682" source="SECTRACK">1006682</ref>
      <ref url="http://www.securitytracker.com/id?1005882" source="SECTRACK">1005882</ref>
      <ref url="http://www.securityfocus.com/bid/6509" source="BID">6509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1072" published="2003-04-28" name="CVE-2003-1072" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/8686/" source="SECUNIA" patch="1">8686</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11895" source="XF">sun-lofiadm-dos(11895)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54100-1" source="SUNALERT" adv="1">54100</ref>
      <ref url="http://www.securityfocus.com/bid/7454" source="BID">7454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1073" published="2003-12-31" name="CVE-2003-1073" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/7960/" source="SECUNIA" patch="1">7960</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11180" source="XF">solaris-at-race-condition(11180)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50161-1" source="SUNALERT" adv="1">50161</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11179" source="XF">solaris-at-directory-traversal(11179)</ref>
      <ref url="http://www.securitytracker.com/id?1005994" source="SECTRACK">1005994</ref>
      <ref url="http://www.securityfocus.com/bid/6693" source="BID">6693</ref>
      <ref url="http://www.securityfocus.com/bid/6692" source="BID">6692</ref>
      <ref url="http://www.securityfocus.com/archive/1/308577" source="BUGTRAQ">20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-070.shtml" source="CIAC">N-070</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0008-sun-at.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0008-sun-at.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0044.html" source="VULNWATCH">20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1074" published="2003-03-28" name="CVE-2003-1074" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/8454/" source="SECUNIA" patch="1">8454</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11657" source="XF" adv="1">solaris-newtask-root-access(11657)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52111-1" source="SUNALERT" adv="1">52111</ref>
      <ref url="http://www.securitytracker.com/id?1006411" source="SECTRACK">1006411</ref>
      <ref url="http://www.securityfocus.com/bid/7252" source="BID">7252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1075" published="2003-01-27" name="CVE-2003-1075" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50240-1" source="SUNALERT" patch="1" adv="1">50240</ref>
      <ref url="http://secunia.com/advisories/7968/" source="SECUNIA" patch="1" adv="1">7968</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11186" source="XF" adv="1">solaris-ftpd-dos(11186)</ref>
      <ref url="http://www.securitytracker.com/id?1005996" source="SECTRACK">1005996</ref>
      <ref url="http://www.securityfocus.com/bid/6709" source="BID">6709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1076" published="2003-12-31" name="CVE-2003-1076" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/8235/" source="SECUNIA" patch="1">8235</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11496" source="XF">solaris-sendmail-forward-privileges(11496)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-050.shtml" source="CIAC">N-050</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50904-1" source="SUNALERT" adv="1">50904</ref>
      <ref url="http://www.securitytracker.com/id?1006234" source="SECTRACK">1006234</ref>
      <ref url="http://www.securityfocus.com/bid/7033" source="BID">7033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1077" published="2003-03-05" name="CVE-2003-1077" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51300-1" source="SUNALERT" patch="1" adv="1">51300</ref>
      <ref url="http://secunia.com/advisories/8234/" source="SECUNIA" patch="1" adv="1">8234</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11481" source="XF" adv="1">solaris-ufs-logging-dos(11481)</ref>
      <ref url="http://www.securitytracker.com/id?1006233" source="SECTRACK">1006233</ref>
      <ref url="http://www.securityfocus.com/bid/7032" source="BID">7032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1078" published="2003-02-28" name="CVE-2003-1078" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11436" source="XF" patch="1" adv="1">solaris-ftp-plaintext-password(11436)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1" source="SUNALERT" patch="1" adv="1">51081</ref>
      <ref url="http://secunia.com/advisories/8186/" source="SECUNIA" patch="1" adv="1">8186</ref>
      <ref url="http://www.securitytracker.com/id?1006195" source="SECTRACK">1006195</ref>
      <ref url="http://www.securityfocus.com/bid/6989" source="BID">6989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1079" published="2003-02-18" name="CVE-2003-1079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11368" source="XF" patch="1" adv="1">solaris-udp-rpc-dos(11368)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50626-1" source="SUNALERT" patch="1" adv="1">50626</ref>
      <ref url="http://secunia.com/advisories/8092/" source="SECUNIA" patch="1" adv="1">8092</ref>
      <ref url="http://www.securitytracker.com/id?1006131" source="SECTRACK">1006131</ref>
      <ref url="http://www.securityfocus.com/bid/6883" source="BID">6883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1080" published="2003-02-11" name="CVE-2003-1080" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11303" source="XF" patch="1" adv="1">solaris-mail-unauthorized-access(11303)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50751-1" source="SUNALERT" patch="1" adv="1">50751</ref>
      <ref url="http://secunia.com/advisories/8058/" source="SECUNIA" patch="1" adv="1">8058</ref>
      <ref url="http://www.securitytracker.com/id?1006084" source="SECTRACK">1006084</ref>
      <ref url="http://www.securityfocus.com/bid/6838" source="BID">6838</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1081" published="2003-09-09" name="CVE-2003-1081" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/o-001.shtml" source="CIAC" adv="1">O-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/10105" source="XF" patch="1" adv="1">solaris-aspppls-tmpfile-symlink(10105)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-46903-1" source="SUNALERT" patch="1" adv="1">46903</ref>
      <ref url="http://www.kb.cert.org/vuls/id/464817" source="CERT-VN" adv="1">VU#464817</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3411&amp;cid=1" source="AUSCERT" adv="1">ESB-2003.0621</ref>
      <ref url="http://www.securityfocus.com/bid/5698" source="BID">5698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1082" published="2003-12-31" name="CVE-2003-1082" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/596748" source="CERT-VN" adv="1">VU#596748</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11083" source="XF">solaris-utmp-update-bo(11083)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-105.shtml" source="CIAC">N-105</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50008-1" source="SUNALERT" adv="1">50008</ref>
      <ref url="http://www.securitytracker.com/id?1005935" source="SECTRACK">1005935</ref>
      <ref url="http://www.securityfocus.com/bid/6639" source="BID">6639</ref>
      <ref url="http://secunia.com/advisories/7892" source="SECUNIA">7892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1083" published="2003-12-31" name="CVE-2003-1083" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/623854" source="CERT-VN">VU#623854</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13817" source="XF" patch="1">monit-http-bo(13817)</ref>
      <ref url="http://www.securityfocus.com/bid/9099" source="BID" patch="1">9099</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-14.xml" source="GENTOO" patch="1">GLSA-200403-14</ref>
      <ref url="http://secunia.com/advisories/10280" source="SECUNIA" patch="1">10280</ref>
      <ref url="http://www.tildeslash.com/monit/dist/CHANGES.txt" source="CONFIRM">http://www.tildeslash.com/monit/dist/CHANGES.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/345417" source="BUGTRAQ" adv="1">20031124 Monit 4.1 HTTP interface multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tildeslash" name="monit">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1084" published="2003-11-24" name="CVE-2003-1084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/206382" source="CERT-VN" adv="1">VU#206382</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13818" source="XF" patch="1" adv="1">monit-negative-content-dos(13818)</ref>
      <ref url="http://www.securityfocus.com/bid/9098" source="BID" patch="1" adv="1">9098</ref>
      <ref url="http://www.securityfocus.com/archive/1/345417" source="BUGTRAQ" patch="1" adv="1">20031124 Monit 4.1 HTTP interface multiple security vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/10280" source="SECUNIA" patch="1" adv="1">10280</ref>
      <ref url="http://www.tildeslash.com/monit/dist/CHANGES.txt" source="CONFIRM" adv="1">http://www.tildeslash.com/monit/dist/CHANGES.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-14.xml" source="GENTOO" adv="1">GLSA-200403-14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tildeslash" name="monit">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1085" published="2003-12-31" name="CVE-2003-1085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13815" source="XF">thomson-http-get-dos(13815)</ref>
      <ref url="http://www.shellsec.net/leer_advisory.php?id=2" source="MISC">http://www.shellsec.net/leer_advisory.php?id=2</ref>
      <ref url="http://www.securityfocus.com/bid/9091" source="BID">9091</ref>
      <ref url="http://www.securityfocus.com/archive/1/345414" source="BUGTRAQ">20031123 Thomnson TCM315 Denial of service</ref>
      <ref url="http://secunia.com/advisories/14353" source="SECUNIA">14353</ref>
      <ref url="http://secunia.com/advisories/10286" source="SECUNIA">10286</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110880725322192&amp;w=2" source="FULLDISC">20050219 Thomson TCW690 Denial Of Service Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110888093214678&amp;w=2" source="BUGTRAQ">20050219 Re: [Full-Disclosure] Thomson TCW690 Denial Of Service Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014068.html" source="FULLDISC">20031124 Thomnson TCM315 Denial of service</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014062.html" source="FULLDISC">20031123 Thomnson TCM315 Denial of service</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1086" published="2003-06-17" name="CVE-2003-1086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pmachine.com/forum/threads.php?id=7274_0_13_0_C" source="CONFIRM" patch="1">http://www.pmachine.com/forum/threads.php?id=7274_0_13_0_C</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638414205498&amp;w=2" source="BUGTRAQ" patch="1">20030623 pMachine (PHP) : Include() Security Hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmachine" name="pmachine_free">
        <vers num="" />
      </prod>
      <prod vendor="pmachine" name="pmachine_pro">
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1087" published="2003-12-31" name="CVE-2003-1087" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7827" source="BID" patch="1">7827</ref>
      <ref url="http://secunia.com/advisories/8971" source="SECUNIA" patch="1">8971</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109292319608851&amp;w=2" source="HP" patch="1">SSRT3460</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12199" source="XF">hp-diagmond-dos(12199)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1088" published="2003-08-11" name="CVE-2003-1088" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12867" source="XF" adv="1">zorum-index-xss(12867)</ref>
      <ref url="http://www.securityfocus.com/bid/8388" source="BID" adv="1">8388</ref>
      <ref url="http://securitytracker.com/id?1013365" source="SECTRACK" adv="1">1013365</ref>
      <ref url="http://secunia.com/advisories/9497" source="SECUNIA" adv="1">9497</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106063199925536&amp;w=2" source="BUGTRAQ" adv="1">20030811 ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="zorum">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1089" published="2003-12-31" name="CVE-2003-1089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12868" source="XF">zorum-index-path-disclosure(12868)</ref>
      <ref url="http://www.securityfocus.com/bid/8396" source="BID">8396</ref>
      <ref url="http://securitytracker.com/id?1013365" source="SECTRACK">1013365</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106063199925536&amp;w=2" source="BUGTRAQ">20030811 ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpoutsourcing" name="zorum">
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1090" published="2003-02-06" name="CVE-2003-1090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/666073" source="CERT-VN" patch="1" adv="1">VU#666073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11265" source="XF" patch="1" adv="1">absolutetelnet-title-bar-bo(11265)</ref>
      <ref url="http://www.securityfocus.com/bid/6785" source="BID" patch="1" adv="1">6785</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104454984001076&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030206 AbsoluteTelnet 2.00 buffer overflow.</ref>
      <ref url="http://www.osvdb.org/16024" source="OSVDB">16024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="celestial_software" name="absolutetelnet">
        <vers num="2.0" />
        <vers num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1091" published="2003-12-31" name="CVE-2003-1091" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/148564" source="CERT-VN" adv="1">VU#148564</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12054" source="XF">darwin-mp3broadcaster-code-execution(12054)</ref>
      <ref url="http://www.securityfocus.com/bid/7660" source="BID">7660</ref>
      <ref url="http://securitytracker.com/id?1006822" source="SECTRACK">1006822</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0245.html" source="BUGTRAQ">20030522 QuickTime/Darwin Streaming Server security issues</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1092" published="2003-12-31" name="CVE-2003-1092" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/100937" source="CERT-VN" adv="1">VU#100937</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11488" source="XF">file-afctr-memory-allocation(11488)</ref>
      <ref url="http://www.securityfocus.com/bid/7009" source="BID">7009</ref>
      <ref url="http://www.securityfocus.com/archive/1/313847" source="OPENPKG">OpenPKG-SA-2003.017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christos_zoulas" name="file_1">
        <vers num="3.28" />
        <vers num="3.30" />
        <vers num="3.32" />
        <vers num="3.33" />
        <vers num="3.34" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="3.37" />
        <vers num="3.39" />
        <vers num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1093" published="2003-12-31" name="CVE-2003-1093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/331937" source="CERT-VN" adv="1">VU#331937</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11057" source="XF" patch="1">weblogic-error-password-disclosure(11057)</ref>
      <ref url="http://www.securityfocus.com/bid/6586" source="BID" patch="1">6586</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-24.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-24.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp3" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1094" published="2003-12-31" name="CVE-2003-1094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/999788" source="CERT-VN" adv="1">VU#999788</ref>
      <ref url="http://www.securityfocus.com/bid/8320" source="BID" patch="1">8320</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12799" source="XF">weblogic-gain-privileges(12799)</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp3:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1095" published="2003-03-18" name="CVE-2003-1095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/691153" source="CERT-VN" patch="1" adv="1">VU#691153</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11555" source="XF" patch="1" adv="1">weblogic-app-reauthentication-bypass(11555)</ref>
      <ref url="http://www.securityfocus.com/bid/7130" source="BID" patch="1" adv="1">7130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1096" published="2003-12-31" name="CVE-2003-1096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/473108" source="CERT-VN" adv="1">VU#473108</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12804" source="XF">cisco-leap-dictionary(12804)</ref>
      <ref url="http://www.securityfocus.com/bid/8755" source="BID">8755</ref>
      <ref url="http://www.securityfocus.com/archive/1/340365" source="BUGTRAQ">20031006 Weaknesses in LEAP Challenge/Response</ref>
      <ref url="http://www.securityfocus.com/archive/1/340119" source="BUGTRAQ">20031003 Dictionary attack against Cisco's LEAP, Wireless LANs vulnerable</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20030802-leap.shtml" source="CISCO" adv="1">20030803 Dictionary Attack on Cisco LEAP Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108135227731965&amp;w=2" source="BUGTRAQ">20040407 Release of Cisco Attack tool Asleap</ref>
      <ref url="http://www.osvdb.org/15209" source="OSVDB">15209</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="leap">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1097" published="2003-12-31" name="CVE-2003-1097" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-5MJKM4" source="HP" patch="1" adv="1">HPSBUX0304-257</ref>
      <ref url="http://www.kb.cert.org/vuls/id/322540" source="CERT-VN" adv="1">VU#322540</ref>
      <ref url="http://www.securityfocus.com/bid/7459" source="BID" patch="1">7459</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-088.shtml" source="CIAC" patch="1">N-088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11890" source="XF">hp-rexec-command-bo(11890)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5611" source="OVAL">oval:org.mitre.oval:def:5611</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0374.html" source="BUGTRAQ">20030429 HPUX rexec buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.26" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1098" published="2003-12-31" name="CVE-2003-1098" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/IAFY-5HVQDJ" source="HP" patch="1" adv="1">HPSBUX0301-238</ref>
      <ref url="http://www.kb.cert.org/vuls/id/862401" source="CERT-VN" adv="1">VU#862401</ref>
      <ref url="http://www.securityfocus.com/bid/6638" source="BID" patch="1">6638</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11094" source="XF">hp-xserver-gain-privileges(11094)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5765" source="OVAL">oval:org.mitre.oval:def:5765</ref>
      <ref url="http://www.securitytracker.com/id?1005936" source="SECTRACK">1005936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1099" published="2003-12-31" name="CVE-2003-1099" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-5VFQA3" source="HP" patch="1" adv="1">HPSBUX0312-304</ref>
      <ref url="http://www.kb.cert.org/vuls/id/509454" source="CERT-VN" adv="1">VU#509454</ref>
      <ref url="http://www.securityfocus.com/bid/9141" source="BID" patch="1">9141</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-032.shtml" source="CIAC" patch="1">O-032</ref>
      <ref url="http://secunia.com/advisories/10339" source="SECUNIA" patch="1">10339</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13882" source="XF">hp-shar-tmpfile-symlink(13882)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5788" source="OVAL">oval:org.mitre.oval:def:5788</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1100" published="2003-12-31" name="CVE-2003-1100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/488684" source="CERT-VN" patch="1" adv="1">VU#488684</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13399" source="XF" patch="1">hummingbird-docsfusionserver-multiple-xss(13399)</ref>
      <ref url="http://secunia.com/advisories/9985" source="SECUNIA" patch="1">9985</ref>
      <ref url="http://www.securityfocus.com/bid/8815" source="BID">8815</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0305.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0305.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="cyberdocs">
        <vers num="3.5.1" />
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1101" published="2003-12-31" name="CVE-2003-1101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/715548" source="CERT-VN" patch="1" adv="1">VU#715548</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13398" source="XF" patch="1">Hummingbird-docsfusionserver-disclose-path(13398)</ref>
      <ref url="http://secunia.com/advisories/9985" source="SECUNIA" patch="1">9985</ref>
      <ref url="http://www.securityfocus.com/bid/8816" source="BID">8816</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0303.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0303.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="cyberdocs">
        <vers num="3.5.1" />
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1102" published="2003-12-31" name="CVE-2003-1102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/989580" source="CERT-VN" patch="1" adv="1">VU#989580</ref>
      <ref url="http://secunia.com/advisories/9985" source="SECUNIA" patch="1">9985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13397" source="XF">Hummingbird-docsfusionserver-file-access(13397)</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0302.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0302.html</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1103" published="2003-12-31" name="CVE-2003-1103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/368300" source="CERT-VN" adv="1">VU#368300</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13401" source="XF" patch="1">hummingbird-docsfusionserver-sql-injection(13401)</ref>
      <ref url="http://secunia.com/advisories/9985" source="SECUNIA" patch="1">9985</ref>
      <ref url="http://www.securityfocus.com/bid/8800" source="BID">8800</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0304.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="cyberdocs">
        <vers num="3.1" />
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1104" published="2003-12-31" name="CVE-2003-1104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/210937" source="CERT-VN" patch="1" adv="1">VU#210937</ref>
      <ref url="http://www.securityfocus.com/bid/7154" source="BID" patch="1">7154</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0307.html" source="BUGTRAQ" patch="1">20030320 IBM Tivoli Firewall Security Toolbox buffer overflow vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11584" source="XF">tivoli-tfst-relay-bo(11584)</ref>
      <ref url="http://secunia.com/advisories/8349" source="SECUNIA">8349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_firewall_toolbox">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1105" published="2003-12-31" name="CVE-2003-1105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/813208" source="CERT-VN" adv="1">VU#813208</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13029" source="XF">ie-input-type-dos(13029)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS">MS03-032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp3" />
        <vers num="5.5" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1106" published="2003-12-31" name="CVE-2003-1106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/155252" source="CERT-VN" adv="1">VU#155252</ref>
      <ref url="http://support.microsoft.com/default.aspx?kbid=330716" source="MSKB">330716</ref>
      <ref url="http://www.securityfocus.com/bid/8195" source="BID">8195</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1107" published="2003-12-31" name="CVE-2003-1107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/222044" source="CERT-VN">VU#222044</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;en-us;828026" source="MSKB" patch="1">828026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13375" source="XF">mediaplayer-dhtml-code-execution(13375)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.4" />
        <vers num="7" />
        <vers num="7.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1108" published="2003-12-31" name="CVE-2003-1108" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID">6904</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5831" source="OVAL">oval:org.mitre.oval:def:5831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel-lucent" name="omnipcx">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1109" published="2003-12-31" name="CVE-2003-1109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID" patch="1">6904</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml" source="CISCO" patch="1">20030221 Multiple Product Vulnerabilities Found by PROTOS SIP Test Suite</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref url="http://www.securitytracker.com/id?1006145" source="SECTRACK">1006145</ref>
      <ref url="http://www.securitytracker.com/id?1006144" source="SECTRACK">1006144</ref>
      <ref url="http://www.securitytracker.com/id?1006143" source="SECTRACK">1006143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ip_phone_7940">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ip_phone_7960">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(1)xa" />
        <vers num="12.2(1)xd" />
        <vers num="12.2(1)xd1" />
        <vers num="12.2(1)xd3" />
        <vers num="12.2(1)xd4" />
        <vers num="12.2(1)xe" />
        <vers num="12.2(1)xe2" />
        <vers num="12.2(1)xe3" />
        <vers num="12.2(1)xh" />
        <vers num="12.2(1)xq" />
        <vers num="12.2(1)xs" />
        <vers num="12.2(1)xs1" />
        <vers num="12.2(11)t" />
        <vers num="12.2(2)t4" />
        <vers num="12.2(2)xa" />
        <vers num="12.2(2)xa1" />
        <vers num="12.2(2)xa5" />
        <vers num="12.2(2)xb" />
        <vers num="12.2(2)xb3" />
        <vers num="12.2(2)xb4" />
        <vers num="12.2(2)xf" />
        <vers num="12.2(2)xg" />
        <vers num="12.2(2)xh" />
        <vers num="12.2(2)xh2" />
        <vers num="12.2(2)xh3" />
        <vers num="12.2(2)xi" />
        <vers num="12.2(2)xi1" />
        <vers num="12.2(2)xi2" />
        <vers num="12.2(2)xj" />
        <vers num="12.2(2)xj1" />
        <vers num="12.2(2)xk" />
        <vers num="12.2(2)xk2" />
        <vers num="12.2(2)xn" />
        <vers num="12.2(2)xt" />
        <vers num="12.2(2)xt3" />
        <vers num="12.2(2)xu" />
        <vers num="12.2(2)xu2" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xw" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="5.2(1)" />
        <vers num="5.2(2)" />
        <vers num="5.2(3.210)" />
        <vers num="5.2(5)" />
        <vers num="5.2(6)" />
        <vers num="5.2(7)" />
        <vers num="5.3" />
        <vers num="5.3(1)" />
        <vers num="5.3(1.200)" />
        <vers num="5.3(2)" />
        <vers num="5.3(3)" />
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.1(2)" />
        <vers num="6.2(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1110" published="2003-12-31" name="CVE-2003-1110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://www.cs.columbia.edu/~xiaotaow/sipc/ouspg.html" source="CONFIRM" patch="1">http://www.cs.columbia.edu/~xiaotaow/sipc/ouspg.html</ref>
      <ref url="http://securitytracker.com/id?1006167" source="SECTRACK" patch="1">1006167</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID">6904</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="columbia_university" name="sipc">
        <vers num="1.74" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1111" published="2003-12-31" name="CVE-2003-1111" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in multiple dynamicsoft products including y and certain demo products for AppEngine allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID">6904</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref url="http://www.dynamicsoft.com/support/advisory/ca-2003-06.php" source="CONFIRM" adv="1">http://www.dynamicsoft.com/support/advisory/ca-2003-06.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dynamicsoft" name="appengine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1112" published="2003-12-31" name="CVE-2003-1112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID" patch="1">6904</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ingate" name="ingate_firewall">
        <vers num="" />
      </prod>
      <prod vendor="ingate" name="ingate_siparator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1113" published="2003-12-31" name="CVE-2003-1113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID" patch="1">6904</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.iptel.org/ser/security/" source="CONFIRM">http://www.iptel.org/ser/security/</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iptel" name="sip_express_router">
        <vers num="0.8.8" />
        <vers num="0.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1114" published="2003-12-31" name="CVE-2003-1114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID">6904</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediatrix_telecom" name="voip_access_devices_and_gateways">
        <vers num="sipv2.3" />
        <vers num="sipv2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1115" published="2003-12-31" name="CVE-2003-1115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/528719" source="CERT-VN" adv="1">VU#528719</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-06.html" source="CERT" adv="1">CA-2003-06</ref>
      <ref url="http://www.securityfocus.com/bid/6904" source="BID" patch="1">6904</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11379" source="XF">sip-invite(11379)</ref>
      <ref url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/" source="MISC">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="succession_communication_server_2000">
        <vers num="" edition=":compact" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1116" published="2003-12-31" name="CVE-2003-1116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/168873" source="CERT-VN" adv="1">VU#168873</ref>
      <ref url="http://www.securityfocus.com/bid/7325" source="BID" patch="1">7325</ref>
      <ref url="http://securitytracker.com/id?1006550" source="SECTRACK" patch="1">1006550</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11768" source="XF">oracle-rra-authentication-bypass(11768)</ref>
      <ref url="http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm" source="MISC">http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105012832418415&amp;w=2" source="BUGTRAQ">20030411 Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="10.7" />
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="11.2" />
        <vers num="11.3" />
        <vers num="11.4" />
        <vers num="11.5" />
        <vers num="11.6" />
        <vers num="11.7" />
        <vers num="11.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1117" published="2003-12-31" name="CVE-2003-1117" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/143627" source="CERT-VN" patch="1" adv="1">VU#143627</ref>
      <ref url="http://www.kb.cert.org/vuls/id/912219" source="CERT-VN">VU#912219</ref>
      <ref url="http://service.real.com/help/faq/security/bufferoverflow.html" source="CONFIRM" patch="1">http://service.real.com/help/faq/security/bufferoverflow.html</ref>
      <ref url="http://securitytracker.com/id?1003604" source="SECTRACK" patch="1">1003604</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11362" source="XF">realsystem-malformed-url-bo(11362)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realsystem_proxy">
        <vers num="8" />
      </prod>
      <prod vendor="realnetworks" name="realsystem_server">
        <vers num="6" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1118" published="2003-12-31" name="CVE-2003-1118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/146785" source="CERT-VN" patch="1" adv="1">VU#146785</ref>
      <ref url="http://www.securityfocus.com/bid/7292" source="BID" patch="1">7292</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11731" source="XF">seti@home-newline-bo(11731)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004383.html" source="FULLDISC">20030406 Seti@home information leakage and remote compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_california" name="seti_at_home">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1119" published="2003-12-31" name="CVE-2003-1119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/333980" source="CERT-VN" adv="1">VU#333980</ref>
      <ref url="http://www.ssh.com/company/newsroom/article/476/" source="CONFIRM" patch="1">http://www.ssh.com/company/newsroom/article/476/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="secure_shell">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1120" published="2003-12-31" name="CVE-2003-1120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/814198" source="CERT-VN" patch="1" adv="1">VU#814198</ref>
      <ref url="http://www.ssh.com/company/newsroom/article/520/" source="CONFIRM" patch="1">http://www.ssh.com/company/newsroom/article/520/</ref>
      <ref url="http://www.securityfocus.com/bid/9956" source="BID" patch="1">9956</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15585" source="XF">sshtectiaserver-passwdplugin-race-condition(15585)</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=4491" source="OSVDB">4491</ref>
      <ref url="http://securitytracker.com/alerts/2004/Mar/1009532.html" source="SECTRACK">1009532</ref>
      <ref url="http://secunia.com/advisories/11193" source="SECUNIA">11193</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="tectia_server">
        <vers num="4.0.3" />
        <vers num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1121" published="2003-12-31" name="CVE-2003-1121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-5EXQSV" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/CRDY-5EXQSV</ref>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-5EXQRP" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/CRDY-5EXQRP</ref>
      <ref url="http://www.kb.cert.org/vuls/id/609137" source="CERT-VN" adv="1">VU#609137</ref>
      <ref url="http://www.kb.cert.org/vuls/id/231705" source="CERT-VN" adv="1">VU#231705</ref>
      <ref url="http://www.securityfocus.com/bid/7477" source="BID" patch="1">7477</ref>
      <ref url="http://www.securityfocus.com/bid/7475" source="BID" patch="1">7475</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11921" source="XF">scriptlogic-runadmin-admin-access(11921)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11920" source="XF">scriptlogic-rpc-modify-registry(11920)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1122" published="2003-12-31" name="CVE-2003-1122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-5EXQT9" source="MISC">http://www.kb.cert.org/vuls/id/CRDY-5EXQT9</ref>
      <ref url="http://www.kb.cert.org/vuls/id/813737" source="CERT-VN">VU#813737</ref>
      <ref url="http://www.securityfocus.com/bid/7476" source="BID" patch="1">7476</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11922" source="XF">scriptlogic-logs$-insecure-permissions(11922)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptlogic" name="scriptlogic">
        <vers num="4.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1123" published="2003-12-31" name="CVE-2003-1123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/393292" source="CERT-VN" patch="1" adv="1">VU#393292</ref>
      <ref url="http://www.securityfocus.com/bid/7824" source="BID" patch="1">7824</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55100-1" source="SUNALERT" patch="1" adv="1">55100</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12189" source="XF">sun-applet-access-information(12189)</ref>
      <ref url="http://securitytracker.com/id?1006935" source="SECTRACK">1006935</ref>
      <ref url="http://secunia.com/advisories/8958" source="SECUNIA">8958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.2.2" edition="" />
        <vers num="1.2.2" edition=":solaris" />
        <vers num="1.2.2_10" edition="" />
        <vers num="1.2.2_10" edition=":solaris" />
        <vers num="1.2.2_10" edition=":windows" />
        <vers num="1.2.2_10" edition=":linux" />
        <vers num="1.2.2_11" edition="" />
        <vers num="1.2.2_11" edition=":linux" />
        <vers num="1.2.2_11" edition=":windows" />
        <vers num="1.2.2_11" edition=":solaris" />
        <vers num="1.2.2_12" edition="" />
        <vers num="1.2.2_12" edition=":windows" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":solaris" />
        <vers num="1.3.0_02" edition="" />
        <vers num="1.3.0_02" edition=":windows" />
        <vers num="1.3.0_02" edition=":solaris" />
        <vers num="1.3.0_02" edition=":linux" />
        <vers num="1.3.0_05" edition="" />
        <vers num="1.3.0_05" edition=":windows" />
        <vers num="1.3.0_05" edition=":linux" />
        <vers num="1.3.0_05" edition=":solaris" />
        <vers num="1.3.1_01" edition="" />
        <vers num="1.3.1_01" edition=":linux" />
        <vers num="1.3.1_01" edition=":solaris" />
        <vers num="1.3.1_01a" edition="" />
        <vers num="1.3.1_01a" edition=":windows" />
        <vers num="1.3.1_03" edition="" />
        <vers num="1.3.1_03" edition=":solaris" />
        <vers num="1.3.1_03" edition=":windows" />
        <vers num="1.3.1_03" edition=":linux" />
        <vers num="1.3.1_04" edition="" />
        <vers num="1.3.1_04" edition=":windows" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":solaris" />
        <vers num="1.4" edition=":linux" />
        <vers num="1.4" edition=":windows" />
        <vers num="1.4.0_01" edition="" />
        <vers num="1.4.0_01" edition=":windows" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.2.2" edition="" />
        <vers num="1.2.2" edition=":solaris" />
        <vers num="1.2.2" edition=":windows" />
        <vers num="1.2.2" edition="update10" />
        <vers num="1.2.2" edition="update10:linux" />
        <vers num="1.2.2" edition="update10:solaris" />
        <vers num="1.2.2" edition="update10:windows" />
        <vers num="1.2.2_003" edition="" />
        <vers num="1.2.2_003" edition=":linux" />
        <vers num="1.2.2_011" edition="" />
        <vers num="1.2.2_011" edition=":solaris" />
        <vers num="1.2.2_011" edition=":linux" />
        <vers num="1.2.2_011" edition=":windows" />
        <vers num="1.2.2_012" edition="" />
        <vers num="1.2.2_012" edition=":solaris" />
        <vers num="1.3.0" edition="" />
        <vers num="1.3.0" edition=":solaris" />
        <vers num="1.3.0" edition=":windows" />
        <vers num="1.3.0" edition=":linux" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update2:linux" />
        <vers num="1.3.0" edition="update2:windows" />
        <vers num="1.3.0" edition="update2:solaris" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update4:windows" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.0" edition="update5:linux" />
        <vers num="1.3.0" edition="update5:solaris" />
        <vers num="1.3.0" edition="update5:windows" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":linux" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update1:linux" />
        <vers num="1.3.1" edition="update1:windows" />
        <vers num="1.3.1" edition="update1:solaris" />
        <vers num="1.3.1" edition="update4" />
        <vers num="1.3.1" edition="update4:windows" />
        <vers num="1.3.1" edition="update4:solaris" />
        <vers num="1.3.1_03" edition="" />
        <vers num="1.3.1_03" edition=":windows" />
        <vers num="1.3.1_03" edition=":solaris" />
        <vers num="1.3.1_03" edition=":linux" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":linux" />
        <vers num="1.4" edition=":solaris" />
        <vers num="1.4" edition=":windows" />
        <vers num="1.4.0_01" edition="" />
        <vers num="1.4.0_01" edition=":windows" />
        <vers num="1.4.0_01" edition=":solaris" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1124" published="2003-12-31" name="CVE-2003-1124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/758932" source="CERT-VN" patch="1" adv="1">VU#758932</ref>
      <ref url="http://www.securityfocus.com/bid/7960" source="BID" patch="1">7960</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55141-1" source="SUNALERT" patch="1" adv="1">55141</ref>
      <ref url="http://secunia.com/advisories/9073" source="SECUNIA" patch="1">9073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12343" source="XF">sunmc-files-writable-permissions(12343)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="management+center">
        <vers num="2.1.1" />
        <vers num="3.0" />
        <vers num="3.0_revenue_release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1125" published="2003-12-31" name="CVE-2003-1125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/195644" source="CERT-VN" adv="1">VU#195644</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52102-1" source="SUNALERT" patch="1" adv="1">52102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_directory_server">
        <vers num="4.16" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1126" published="2003-12-31" name="CVE-2003-1126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/636964" source="CERT-VN" adv="1">VU#636964</ref>
      <ref url="http://secunia.com/advisories/9541" source="SECUNIA" patch="1">9541</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56180-1" source="SUNALERT" adv="1">56180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1127" published="2003-12-31" name="CVE-2003-1127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/371470" source="CERT-VN" adv="1">VU#371470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14869" source="XF">egap-url-information-disclosure(14869)</ref>
      <ref url="http://www.securityfocus.com/bid/9431" source="BID">9431</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0307.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0307.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whale_communications" name="e-gap">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1128" published="2003-12-31" name="CVE-2003-1128" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/583020" source="CERT-VN" patch="1" adv="1">VU#583020</ref>
      <ref url="http://www.securityfocus.com/bid/7534" source="BID" patch="1">7534</ref>
      <ref url="http://secunia.com/advisories/8775" source="SECUNIA" patch="1">8775</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12139" source="XF">xmms-remote-command-execution(12139)</ref>
      <ref url="http://www.x2studios.com/index.php?page=kb&amp;id=16" source="CONFIRM">http://www.x2studios.com/index.php?page=kb&amp;id=16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x2_studios" name="xmms_remote">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1129" published="2003-12-31" name="CVE-2003-1129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/272644" source="CERT-VN" adv="1">VU#272644</ref>
      <ref url="http://www.securityfocus.com/archive/1/323439" source="BUGTRAQ" patch="1">20030530 Yahoo! Security Advisory: Yahoo! Voice Chat</ref>
      <ref url="http://secunia.com/advisories/8924" source="SECUNIA" patch="1">8924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12130" source="XF">yahoo-audio-bo(12130)</ref>
      <ref url="http://www.securityfocus.com/bid/7561" source="BID">7561</ref>
      <ref url="http://help.yahoo.com/help/us/mesg/use/use-45.html" source="CONFIRM">http://help.yahoo.com/help/us/mesg/use/use-45.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="audio_conferencing_activex_control">
        <vers num="1.0.0.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-1130" reject="1" published="2003-12-31" name="CVE-2003-1130" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-1071.  Reason: This candidate is a duplicate of CVE-2003-1071.  Notes: All CVE users should reference CVE-2003-1071 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-1131" published="2003-12-31" name="CVE-2003-1131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9292" source="BID" patch="1">9292</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14078" source="XF">knowledgebuilder-indexphp-file-include(14078)</ref>
      <ref url="http://www.securityfocus.com/archive/1/348359" source="BUGTRAQ">20031224 Remote Code Execution in Knowledge Builder.</ref>
      <ref url="http://secunia.com/advisories/10504" source="SECUNIA" adv="1">10504</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066494323543&amp;w=2" source="BUGTRAQ">20050312 KnowledgeBase</ref>
      <ref url="http://www.osvdb.org/3228" source="OSVDB">3228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecampaign" name="knowledgebuilder">
        <vers num="2.0.1" />
        <vers num="2.1.0" />
        <vers num="2.1.4" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1132" published="2003-12-31" name="CVE-2003-1132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/714121" source="CERT-VN">VU#714121</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030430-dns.shtml" source="CISCO" adv="1">20041008 Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1133" published="2003-12-31" name="CVE-2003-1133" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8891" source="BID">8891</ref>
      <ref url="http://www.securityfocus.com/archive/1/342485" source="BUGTRAQ">20031025 Some serious security holes in 'The Bat!'</ref>
      <ref url="http://securitytracker.com/id?1008004" source="SECTRACK">1008004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ritlabs" name="the_bat">
        <vers num="1.011" />
        <vers num="1.015" />
        <vers num="1.028" />
        <vers num="1.029" />
        <vers num="1.031" />
        <vers num="1.032" />
        <vers num="1.035" />
        <vers num="1.036" />
        <vers num="1.037" />
        <vers num="1.039" />
        <vers num="1.041" />
        <vers num="1.043" />
        <vers num="1.1" />
        <vers num="1.101" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.31" />
        <vers num="1.32" />
        <vers num="1.33" />
        <vers num="1.34" />
        <vers num="1.35" />
        <vers num="1.36" />
        <vers num="1.39" />
        <vers num="1.41" />
        <vers num="1.42" />
        <vers num="1.42f" />
        <vers num="1.43" />
        <vers num="1.44" />
        <vers num="1.45" />
        <vers num="1.46" />
        <vers num="1.47" />
        <vers num="1.48" />
        <vers num="1.49" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53d" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1134" published="2003-12-31" name="CVE-2003-1134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8892" source="BID">8892</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012773.html" source="FULLDISC">20031026 Java 1.4.2_02 InsecurityManager JVM crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="1.3.1" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1135" published="2003-12-31" name="CVE-2003-1135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8894" source="BID">8894</ref>
      <ref url="http://www.securityfocus.com/archive/1/342472" source="BUGTRAQ">20031026 Buffer Overflow in Yahoo messenger Client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1136" published="2003-10-23" name="CVE-2003-1136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13523" source="XF" adv="1">guestbook-doublequotation-xss(13523)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13522" source="XF" adv="1">guestbook-html-xss(13522)</ref>
      <ref url="http://www.securityfocus.com/bid/8896" source="BID" adv="1">8896</ref>
      <ref url="http://www.securityfocus.com/bid/8895" source="BID" adv="1">8895</ref>
      <ref url="http://www.securityfocus.com/archive/1/342475" source="BUGTRAQ" adv="1">20031026 New Vulnerability</ref>
      <ref url="http://www.osvdb.org/2718" source="OSVDB" adv="1">2718</ref>
      <ref url="http://securitytracker.com/id?1008006" source="SECTRACK" adv="1">1008006</ref>
      <ref url="http://secunia.com/advisories/10080" source="SECUNIA" adv="1">10080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chi_kien_uong" name="chi_kien_uong_guestbook">
        <vers num="1.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1137" published="2003-10-27" name="CVE-2003-1137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8897" source="BID" patch="1" adv="1">8897</ref>
      <ref url="http://www.securityfocus.com/archive/1/342766" source="BUGTRAQ" patch="1">20031028 Re: sh-httpd `wildcard character' vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/342473" source="BUGTRAQ" patch="1" adv="1">20031027 sh-httpd `wildcard character' vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13519" source="XF" adv="1">shtttpd-get-information-disclosure(13519)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="charles_steinkuehler" name="sh-httpd">
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1138" published="2003-10-27" name="CVE-2003-1138" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8898" source="BID" adv="1">8898</ref>
      <ref url="http://www.securityfocus.com/archive/1/342578" source="BUGTRAQ" adv="1">20031027 Root Directory Listing on RH default apache</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="interchange">
        <vers num="2.0.40_21.5" edition="" />
        <vers num="2.0.40_21.5" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1139" published="2003-10-27" name="CVE-2003-1139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13520" source="XF" adv="1">musicqueue-tmpfile-symlink(13520)</ref>
      <ref url="http://www.securityfocus.com/bid/8899" source="BID" adv="1">8899</ref>
      <ref url="http://www.securityfocus.com/archive/1/342476" source="BUGTRAQ" adv="1">20031027 Musicqueue multiple local vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1008014" source="SECTRACK" adv="1">1008014</ref>
      <ref url="http://secunia.com/advisories/10104" source="SECUNIA" adv="1">10104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicqueue" name="musicqueue">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1140" published="2003-10-27" name="CVE-2003-1140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13521" source="XF" adv="1">musicqueue-getconf-bo(13521)</ref>
      <ref url="http://www.securityfocus.com/bid/8903" source="BID" adv="1">8903</ref>
      <ref url="http://www.securityfocus.com/archive/1/342476" source="BUGTRAQ" adv="1">20031027 Musicqueue multiple local vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1008014" source="SECTRACK" adv="1">1008014</ref>
      <ref url="http://secunia.com/advisories/10104" source="SECUNIA" adv="1">10104</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0021.html" source="VULNWATCH">20031027 Musicqueue multiple local vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicqueue" name="musicqueue">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1141" published="2003-11-04" name="CVE-2003-1141" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13591" source="XF" adv="1">niprint-bo(13591)</ref>
      <ref url="http://www.securityfocus.com/bid/8968" source="BID" adv="1">8968</ref>
      <ref url="http://www.securityfocus.com/archive/1/343318" source="BUGTRAQ">20031104 NIPrint remote exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/343257" source="BUGTRAQ" adv="1">20031104 SRT2003-11-02-0115 - NIPrint LPD-LPR Remote overflow</ref>
      <ref url="http://www.osvdb.org/2774" source="OSVDB" adv="1">2774</ref>
      <ref url="http://secunia.com/advisories/10143" source="SECUNIA" adv="1">10143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_instruments" name="niprint_lpd-lpr_print_server">
        <vers num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1142" published="2003-11-03" name="CVE-2003-1142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13592" source="XF" adv="1">niprint-helpapi-gain-privileges(13592)</ref>
      <ref url="http://www.securityfocus.com/bid/8969" source="BID" adv="1">8969</ref>
      <ref url="http://www.securityfocus.com/archive/1/343258" source="BUGTRAQ" adv="1">20031104 SRT2003-11-02-0218 - NIPrint LPD-LPR Local Help API SYSTEM exploit</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1143" published="2003-10-30" name="CVE-2003-1143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13618" source="XF" patch="1" adv="1">serioussam-games-packet-dos(13618)</ref>
      <ref url="http://www.securityfocus.com/bid/8936" source="BID" patch="1" adv="1">8936</ref>
      <ref url="http://www.securityfocus.com/archive/1/342957" source="BUGTRAQ" patch="1" adv="1">20031030 Serious Sam is not so serious</ref>
    </refs>
    <vuln_soft>
      <prod vendor="croteam" name="serioussam">
        <vers num="test_2_2.1_a" />
        <vers num="the_first_encounter_1.0.5" />
        <vers num="the_second_encounter_1.0.5" />
        <vers num="the_second_encounter_demo" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1144" published="2003-11-04" name="CVE-2003-1144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/2766" source="OSVDB" patch="1" adv="1">2766</ref>
      <ref url="http://secunia.com/advisories/10136" source="SECUNIA" patch="1" adv="1">10136</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13599" source="XF" adv="1">liteserve-log-entry-bo(13599)</ref>
      <ref url="http://www.securityfocus.com/bid/8971" source="BID" adv="1">8971</ref>
      <ref url="http://www.securityfocus.com/archive/1/343322" source="BUGTRAQ" adv="1">20031104 Liteserve Buffer Overflow in Handling Server's Log.</ref>
      <ref url="http://securitytracker.com/id?1008093" source="SECTRACK" adv="1">1008093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perception" name="liteserve">
        <vers num="1.25" />
        <vers num="1.28" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1145" published="2003-11-03" name="CVE-2003-1145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13604" source="XF" adv="1">openautoclassifieds-friendmail-xss(13604)</ref>
      <ref url="http://www.securityfocus.com/bid/8972" source="BID" adv="1">8972</ref>
      <ref url="http://www.securityfocus.com/archive/1/343806" source="BUGTRAQ" adv="1">20031107 OpenAutoClassifieds XSS attack</ref>
      <ref url="http://www.osvdb.org/2767" source="OSVDB" adv="1">2767</ref>
      <ref url="http://secunia.com/advisories/10138" source="SECUNIA" adv="1">10138</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1146" published="2003-05-11" name="CVE-2003-1146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8977" source="BID" adv="1">8977</ref>
      <ref url="http://security.nnov.ru/docs5347.html" source="MISC" adv="1">http://security.nnov.ru/docs5347.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_beatty" name="easy_php_photo_album">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-1147" reject="1" published="2003-12-31" name="CVE-2003-1147" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0955.  Reason: This candidate is a duplicate of CVE-2003-0955.  Notes: All CVE users should reference CVE-2003-0955 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2003-1148" published="2003-10-25" name="CVE-2003-1148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13529" source="XF" patch="1" adv="1">les-visiteurs-file-include(13529)</ref>
      <ref url="http://www.osvdb.org/3586" source="OSVDB" patch="1" adv="1">3586</ref>
      <ref url="http://securitytracker.com/id?1008011" source="SECTRACK" patch="1">1008011</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0262.html" source="BUGTRAQ" patch="1">20031026 Les Visiteurs v2.0.1 code injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/8902" source="BID" adv="1">8902</ref>
      <ref url="http://www.osvdb.org/2717" source="OSVDB" adv="1">2717</ref>
      <ref url="http://securitytracker.com/id?1017065" source="SECTRACK">1017065</ref>
      <ref url="http://secunia.com/advisories/10079" source="SECUNIA" adv="1">10079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="les_visiteurs" name="les_visiteurs">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1149" published="2003-10-27" name="CVE-2003-1149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8904" source="BID" patch="1" adv="1">8904</ref>
      <ref url="http://www.osvdb.org/2714" source="OSVDB" patch="1" adv="1">2714</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13528" source="XF" adv="1">norton-is-blocked-xss(13528)</ref>
      <ref url="http://www.securityfocus.com/archive/1/342548" source="BUGTRAQ" adv="1">20031027 Norton Internet Security 2003 XSS</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html</ref>
      <ref url="http://secunia.com/advisories/10067" source="SECUNIA" adv="1">10067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2003_6.0.4.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1150" published="2003-10-27" name="CVE-2003-1150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13564" source="XF" adv="1">novell-portmapper-bo(13564)</ref>
      <ref url="http://www.securityfocus.com/bid/8907" source="BID" adv="1">8907</ref>
      <ref url="http://secunia.com/advisories/10100" source="SECUNIA" adv="1">10100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_desktops">
        <vers num="3.2" edition="sp2" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1151" published="2003-10-28" name="CVE-2003-1151" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13535" source="XF" adv="1">fastream-nonexistent-url-xss(13535)</ref>
      <ref url="http://www.securityfocus.com/bid/8908" source="BID" adv="1">8908</ref>
      <ref url="http://www.securityfocus.com/archive/1/342678" source="BUGTRAQ" adv="1">20031028 Fastream NetFile FTP/WebServer 6.0 CSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/2732" source="OSVDB" adv="1">2732</ref>
      <ref url="http://securitytracker.com/id?1008020" source="SECTRACK" adv="1">1008020</ref>
      <ref url="http://secunia.com/advisories/10099" source="SECUNIA" adv="1">10099</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1152" published="2003-12-31" name="CVE-2003-1152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13533" source="XF">webtide-file-disclosure(13533)</ref>
      <ref url="http://www.securityfocus.com/bid/8909" source="BID">8909</ref>
      <ref url="http://www.osvdb.org/2719" source="OSVDB">2719</ref>
      <ref url="http://securitytracker.com/id?1008016" source="SECTRACK">1008016</ref>
      <ref url="http://secunia.com/advisories/10078" source="SECUNIA">10078</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012811.html" source="FULLDISC">20031028 STG Security Advisory: [SSA-20031025-05] InfronTech WebTide 7.04 Directory and File Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infrontech" name="webtide">
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1153" published="2003-12-31" name="CVE-2003-1153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10082" source="SECUNIA" patch="1">10082</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13531" source="XF">bytehoard-view-file(13531)</ref>
      <ref url="http://www.securityfocus.com/bid/8910" source="BID">8910</ref>
      <ref url="http://www.osvdb.org/2700" source="OSVDB">2700</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012801.html" source="FULLDISC">20031027 Bytehoard File Disclosure VUlnerability Sequel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bytehoard" name="bytehoard">
        <vers num="0.7" />
        <vers num="0.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1154" published="2003-12-31" name="CVE-2003-1154" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10148" source="SECUNIA" patch="1">10148</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13611" source="XF">mailsweeper-zip-virus-bypass(13611)</ref>
      <ref url="http://www.securityfocus.com/bid/8982" source="BID">8982</ref>
      <ref url="http://www.osvdb.org/2772" source="OSVDB">2772</ref>
      <ref url="http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&amp;More=" source="MISC">http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&amp;More=</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.3.10" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.6_sp1" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1155" published="2003-12-31" name="CVE-2003-1155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8983" source="BID" patch="1">8983</ref>
      <ref url="http://securitytracker.com/id?1008094" source="SECTRACK" patch="1">1008094</ref>
      <ref url="http://secunia.com/advisories/10162" source="SECUNIA" patch="1">10162</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13612" source="XF">xcdroast-symlink(13612)</ref>
      <ref url="http://www.xcdroast.org/xcdr098/changelog-a15.html" source="CONFIRM">http://www.xcdroast.org/xcdr098/changelog-a15.html</ref>
      <ref url="http://www.osvdb.org/2786" source="OSVDB">2786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-cd-roast" name="x-cd-roast">
        <vers num="0.98_alpha10" />
        <vers num="0.98_alpha11" />
        <vers num="0.98_alpha12" />
        <vers num="0.98_alpha13" />
        <vers num="0.98_alpha14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1156" published="2003-12-31" name="CVE-2003-1156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13570" source="XF">sun-jre-java-symlink(13570)</ref>
      <ref url="http://www.securityfocus.com/bid/8937" source="BID">8937</ref>
      <ref url="http://www.securityfocus.com/archive/1/343038" source="BUGTRAQ">20031031 Advisory: Sun's jre/jdk 1.4.2 multiple vulernabilities in linuxinstallers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":linux" />
        <vers num="1.4.2_02" edition="" />
        <vers num="1.4.2_02" edition=":linux" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":linux" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update2:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1157" published="2003-12-31" name="CVE-2003-1157" modified="2009-09-19" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10127" source="SECUNIA" patch="1">10127</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40782" source="XF">citrix-webmanager-login-xss(40782)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13569" source="XF">metaframe-error-message-xss(13569)</ref>
      <ref url="http://www.securityfocus.com/bid/8939" source="BID">8939</ref>
      <ref url="http://www.securityfocus.com/bid/27948" source="BID">27948</ref>
      <ref url="http://www.securityfocus.com/archive/1/343040" source="BUGTRAQ">20031031 IRM 008: Citrix Metaframe XP is vulnerable to Cross Site Scripting</ref>
      <ref url="http://www.osvdb.org/2762" source="OSVDB">2762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":xp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1158" published="2003-12-31" name="CVE-2003-1158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13219" source="XF">plugandplaywebserver-multiple-commands-dos(13219)</ref>
      <ref url="http://www.securityfocus.com/bid/8667" source="BID">8667</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0275.html" source="BUGTRAQ">20030917 Denial Of Service in Plug &amp; Play Web (FTP) Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plug_and_play_software" name="plug_and_play_web_server">
        <vers num="1.0.002c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1159" published="2003-10-31" name="CVE-2003-1159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13572" source="XF" adv="1">plugandplaywebserver-get-dos(13572)</ref>
      <ref url="http://www.securityfocus.com/bid/8941" source="BID" adv="1">8941</ref>
      <ref url="http://www.osvdb.org/2764" source="OSVDB" adv="1">2764</ref>
      <ref url="http://secunia.com/advisories/10131" source="SECUNIA" adv="1">10131</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0343.html" source="BUGTRAQ" adv="1">20031031 DoS in Plug and Play Web Server Proxy Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plug_and_play" name="plug_and_play_web_server_proxy">
        <vers num="1.0002c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1160" published="2003-10-30" name="CVE-2003-1160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/2842" source="OSVDB" patch="1" adv="1">2842</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13567" source="XF" adv="1">flexwatch-slash-admin-access(13567)</ref>
      <ref url="http://www.securityfocus.com/bid/8942" source="BID">8942</ref>
      <ref url="http://securitytracker.com/id?1008049" source="SECTRACK">1008049</ref>
      <ref url="http://secunia.com/advisories/10132" source="SECUNIA" adv="1">10132</ref>
      <ref url="http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt" source="MISC">http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seyeon" name="flexwatch_network_video_server">
        <vers num="2.2" />
        <vers num="model_132" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1161" published="2003-12-31" name="CVE-2003-1161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0630.html" source="MLIST">[linux-kernel] 20031105 Re: BK2CVS problem</ref>
      <ref url="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0627.html" source="MLIST">[linux-kernel] 20031105 Re: BK2CVS problem</ref>
      <ref url="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0621.html" source="MLIST">[linux-kernel] 20031105 BK2CVS problem</ref>
      <ref url="http://www.securityfocus.com/bid/8987" source="BID">8987</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1162" published="2003-12-31" name="CVE-2003-1162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13587" source="XF">tritanium-threadid-view-messages(13587)</ref>
      <ref url="http://www.securityfocus.com/bid/8944" source="BID">8944</ref>
      <ref url="http://www.osvdb.org/2770" source="OSVDB">2770</ref>
      <ref url="http://secunia.com/advisories/10135" source="SECUNIA">10135</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0348.html" source="BUGTRAQ">20031031 Virginity Security Advisory 2003-002 : Tritanium Bulletin Board - Read and write from/to internal (protected) Threads</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tritanium_scripts" name="tritanium_bulletin_board">
        <vers num="0.993_beta" />
        <vers num="0.994_beta" />
        <vers num="0.999_beta" />
        <vers num="1.0_beta" />
        <vers num="1.1_final" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1163" published="2003-12-31" name="CVE-2003-1163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10166" source="SECUNIA" patch="1">10166</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13631" source="XF">ganglia-gmond-dos(13631)</ref>
      <ref url="http://www.securityfocus.com/bid/8988" source="BID">8988</ref>
      <ref url="http://www.securityfocus.com/archive/1/343689" source="BUGTRAQ">20031106 DoS for Ganglia</ref>
      <ref url="http://www.osvdb.org/2787" source="OSVDB">2787</ref>
      <ref url="http://ganglia.sourceforge.net/" source="CONFIRM">http://ganglia.sourceforge.net/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ganglia" name="gmond">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1164" published="2003-12-31" name="CVE-2003-1164" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10134" source="SECUNIA" patch="1">10134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13615" source="XF">mldonkey-xss(13615)</ref>
      <ref url="http://www.securityfocus.com/bid/8946" source="BID">8946</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/013070.html" source="FULLDISC">20031031 XSS In mldonkey - But....</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mldonkey" name="mldonkey">
        <vers num="2.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1165" published="2003-12-31" name="CVE-2003-1165" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13571" source="XF">brswebweaver-useragent-bo(13571)</ref>
      <ref url="http://www.securityfocus.com/bid/8947" source="BID">8947</ref>
      <ref url="http://www.securityfocus.com/archive/1/343111" source="BUGTRAQ">20031101 BRS WebWeaver 1.06 remote DoS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brs" name="webweaver">
        <vers num="0.49_beta" />
        <vers num="0.50_beta" />
        <vers num="0.51_beta" />
        <vers num="0.52_beta" />
        <vers num="0.60_beta" />
        <vers num="0.61_beta" />
        <vers num="0.62_beta" />
        <vers num="0.63_beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1166" published="2003-12-31" name="CVE-2003-1166" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13622" source="XF">http-commander-directory-traversal(13622)</ref>
      <ref url="http://www.securityfocus.com/bid/8948" source="BID">8948</ref>
      <ref url="http://www.osvdb.org/2780" source="OSVDB">2780</ref>
      <ref url="http://www.http-com.com/Default.asp?section=Features" source="CONFIRM">http://www.http-com.com/Default.asp?section=Features</ref>
      <ref url="http://secunia.com/advisories/10125" source="SECUNIA">10125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="http_commander" name="http_commander">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1167" published="2003-12-31" name="CVE-2003-1167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8915" source="BID" patch="1">8915</ref>
      <ref url="http://www.osvdb.org/2742" source="OSVDB" patch="1">2742</ref>
      <ref url="http://secunia.com/advisories/10105" source="SECUNIA" patch="1">10105</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13540" source="XF">kpopup-systemcall-execute-code(13540)</ref>
      <ref url="http://www.securityfocus.com/archive/1/342736" source="BUGTRAQ">20031028 Local root vuln in kpopup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gernot_stocker" name="kpopup">
        <vers num="0.9.1" />
        <vers num="0.9.5_pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1168" published="2003-12-31" name="CVE-2003-1168" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10125" source="SECUNIA" patch="1">10125</ref>
      <ref url="http://www.securityfocus.com/bid/8949" source="BID">8949</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1169" published="2003-12-31" name="CVE-2003-1169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which alows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13589" source="XF" patch="1">nutzungskontrolle-registry-security-bypass(13589)</ref>
      <ref url="http://www.securityfocus.com/bid/8950" source="BID" patch="1">8950</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013113.html" source="FULLDISC" patch="1">20031101 DATEV Nutzungskontrolle Bypassing (REG)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datev" name="nutzungskontrolle">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1170" published="2003-12-31" name="CVE-2003-1170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/342736" source="BUGTRAQ" patch="1">20031028 Local root vuln in kpopup</ref>
      <ref url="http://secunia.com/advisories/10105" source="SECUNIA" patch="1">10105</ref>
      <ref url="http://www.securityfocus.com/bid/8918" source="BID">8918</ref>
      <ref url="http://www.osvdb.org/3290" source="OSVDB">3290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gernot_stocker" name="kpopup">
        <vers num="0.9.1" />
        <vers num="0.9.5_pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1171" published="2003-12-31" name="CVE-2003-1171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13543" source="XF" patch="1">mod-security-secfilterout-bo(13543)</ref>
      <ref url="http://www.securityfocus.com/bid/8919" source="BID" patch="1">8919</ref>
      <ref url="http://www.securityfocus.com/archive/1/342767" source="BUGTRAQ" patch="1">20031028 mod_security 1.7RC1 to 1.7.1 vulnerability</ref>
      <ref url="http://securitytracker.com/id?1008025" source="SECTRACK" patch="1">1008025</ref>
      <ref url="http://secunia.com/advisories/10085" source="SECUNIA" patch="1" adv="1">10085</ref>
      <ref url="http://www.modsecurity.org/download/CHANGES" source="CONFIRM">http://www.modsecurity.org/download/CHANGES</ref>
      <ref url="http://adsystems.com.pl/adg-mod_security171.txt" source="MISC">http://adsystems.com.pl/adg-mod_security171.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_security" name="mod_security">
        <vers num="1.7" />
        <vers num="1.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1172" published="2003-12-31" name="CVE-2003-1172" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/securitynews/6W00L0U8KC.html" source="MISC" patch="1">http://www.securiteam.com/securitynews/6W00L0U8KC.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13499" source="XF">apachecocoon-directory-traversal-bootini(13499)</ref>
      <ref url="http://www.securityfocus.com/bid/8883" source="BID">8883</ref>
      <ref url="http://www.osvdb.org/2749" source="OSVDB">2749</ref>
      <ref url="http://securitytracker.com/id?1007993" source="SECTRACK">1007993</ref>
      <ref url="http://secunia.com/advisories/10064" source="SECUNIA">10064</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=23949" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=23949</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="cocoon">
        <vers num="2.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1173" published="2003-12-31" name="CVE-2003-1173" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13546" source="XF" patch="1">firstclass-view-unauthorized-files(13546)</ref>
      <ref url="http://www.securityfocus.com/bid/8920" source="BID" patch="1">8920</ref>
      <ref url="http://secunia.com/advisories/10084" source="SECUNIA" patch="1">10084</ref>
      <ref url="http://www.securityfocus.com/archive/1/342909" source="BUGTRAQ">20031030 Re: FirstClass 7.1 HTTP Server: Remote Directory Listing</ref>
      <ref url="http://www.securityfocus.com/archive/1/342765" source="BUGTRAQ">20031028 FirstClass 7.1 HTTP Server: Remote Directory Listing</ref>
      <ref url="http://www.osvdb.org/2723" source="OSVDB">2723</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1174" published="2003-12-31" name="CVE-2003-1174" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13586" source="XF">shoutcast-long-icy-dos(13586)</ref>
      <ref url="http://www.securityfocus.com/bid/8954" source="BID">8954</ref>
      <ref url="http://www.securityfocus.com/archive/1/343177" source="BUGTRAQ">20031102 ShoutCast server 1.9.2/win32</ref>
      <ref url="http://www.osvdb.org/2776" source="OSVDB">2776</ref>
      <ref url="http://securitytracker.com/id?1008080" source="SECTRACK">1008080</ref>
      <ref url="http://secunia.com/advisories/10146" source="SECUNIA">10146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="shoutcast_server">
        <vers num="1.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1175" published="2003-12-31" name="CVE-2003-1175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13630" source="XF">sympoll-indexphp-xss(13630)</ref>
      <ref url="http://www.securityfocus.com/bid/8956" source="BID">8956</ref>
      <ref url="http://www.osvdb.org/2790" source="OSVDB">2790</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834374&amp;group_id=64442&amp;atid=507493" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834374&amp;group_id=64442&amp;atid=507493</ref>
      <ref url="http://secunia.com/advisories/10165" source="SECUNIA">10165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="synthetic_reality" name="sympoll">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1176" published="2003-12-31" name="CVE-2003-1176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/343314" source="BUGTRAQ" patch="1">20031104 Re: Unauthorized access in Web Wiz Forum</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13581" source="XF">webwizforums-quotemode-message-access(13581)</ref>
      <ref url="http://www.securityfocus.com/bid/8957" source="BID">8957</ref>
      <ref url="http://www.securityfocus.com/archive/1/343175" source="BUGTRAQ">20031102 Unauthorized access in Web Wiz Forum</ref>
      <ref url="http://www.osvdb.org/2768" source="OSVDB">2768</ref>
      <ref url="http://securitytracker.com/id?1008100" source="SECTRACK">1008100</ref>
      <ref url="http://secunia.com/advisories/10137" source="SECUNIA">10137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bdc_enterprises" name="web_wiz_forums">
        <vers num="6.34" />
        <vers num="7.01" />
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1177" published="2003-12-31" name="CVE-2003-1177" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10038" source="SECUNIA" patch="1">10038</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13468" source="XF">mercur-auth-command-dos(13468)</ref>
      <ref url="http://www.securityfocus.com/bid/8889" source="BID">8889</ref>
      <ref url="http://www.securityfocus.com/bid/8861" source="BID">8861</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html" source="MISC">http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html</ref>
      <ref url="http://www.osvdb.org/2688" source="OSVDB">2688</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q4/1459.html" source="FULLDISC">20031024 Vulnerability in MERCUR Mail Server v4.2 SP3 and below</ref>
      <ref url="http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html" source="CONFIRM">http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_mailserver">
        <vers num="3.3" />
        <vers num="3.3_sp1" />
        <vers num="3.3_sp2" />
        <vers num="4.1" />
        <vers num="4.1_sp1" />
        <vers num="4.2" />
        <vers num="4.2_sp1" />
        <vers num="4.2_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1178" published="2003-12-31" name="CVE-2003-1178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10068" source="SECUNIA" patch="1" adv="1">10068</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29396" source="XF">advanced-poll-comments-file-include(29396)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13513" source="XF">advancedpoll-php-injection(13513)</ref>
      <ref url="http://www.securityfocus.com/bid/8890" source="BID">8890</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/448007/100/0/threaded" source="BUGTRAQ">20061008 Advanced Poll v2.02 :) &lt;= Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/342493" source="BUGTRAQ">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref url="http://www.osvdb.org/2743" source="OSVDB">2743</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-October/001080.html" source="VIM">Advanced Poll v2.02 :) &lt;= Remote File Inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1179" published="2003-12-31" name="CVE-2003-1179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10068" source="SECUNIA" patch="1" adv="1">10068</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13514" source="XF">advancedpoll-php-file-include(13514)</ref>
      <ref url="http://www.solpotcrew.org/adv/solpot-adv-02.txt" source="MISC">http://www.solpotcrew.org/adv/solpot-adv-02.txt</ref>
      <ref url="http://www.securityfocus.com/bid/8890" source="BID">8890</ref>
      <ref url="http://www.securityfocus.com/bid/19105" source="BID">19105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440780/100/0/threaded" source="BUGTRAQ">20060721 SolpotCrew Advisory #2 - Advanced Poll ver 2.02 (base_path) Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/342493" source="BUGTRAQ">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref url="http://www.phpsecure.info/v2/tutos/frog/AdvancedPoll2.0.2.txt" source="MISC">http://www.phpsecure.info/v2/tutos/frog/AdvancedPoll2.0.2.txt</ref>
      <ref url="http://www.osvdb.org/3291" source="OSVDB">3291</ref>
      <ref url="http://www.osvdb.org/28988" source="OSVDB">28988</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1180" published="2003-12-31" name="CVE-2003-1180" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10068" source="SECUNIA" patch="1" adv="1">10068</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13514" source="XF">advancedpoll-php-file-include(13514)</ref>
      <ref url="http://www.securityfocus.com/bid/8890" source="BID">8890</ref>
      <ref url="http://www.securityfocus.com/archive/1/342493" source="BUGTRAQ">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref url="http://www.osvdb.org/3291" source="OSVDB">3291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1181" published="2003-10-25" name="CVE-2003-1181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/342493" source="BUGTRAQ" patch="1">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13515" source="XF" adv="1">advancedpoll-phpinfo-obtain-information(13515)</ref>
      <ref url="http://www.securityfocus.com/bid/8890" source="BID" adv="1">8890</ref>
      <ref url="http://www.osvdb.org/3292" source="OSVDB" adv="1">3292</ref>
      <ref url="http://secunia.com/advisories/10068" source="SECUNIA" adv="1">10068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1182" published="2003-11-03" name="CVE-2003-1182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13575" source="XF" adv="1">mpmguestbook-ing-xss(13575)</ref>
      <ref url="http://www.securityfocus.com/bid/8958" source="BID">8958</ref>
      <ref url="http://www.osvdb.org/2754" source="OSVDB" adv="1">2754</ref>
      <ref url="http://secunia.com/advisories/10122" source="SECUNIA" adv="1">10122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpm" name="mpm_guestbook">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1183" published="2003-10-28" name="CVE-2003-1183" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The WebCache component in Oracle Files 9.0.3.1.0, 9.0.3.2.0, and 9.0.3.3.0 of Oracle Collaboration Suite Release 1 caches files despite the cacheability rules imposed by Oracle Files, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8923" source="BID" patch="1" adv="1">8923</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2003alert60.pdf" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/pdf/2003alert60.pdf</ref>
      <ref url="http://secunia.com/advisories/10088" source="SECUNIA" patch="1" adv="1">10088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13545" source="XF" adv="1">oraclecollaborationsuite-file-access(13545)</ref>
      <ref url="http://www.osvdb.org/2727" source="OSVDB">2727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle_files">
        <vers num="9.0.3.1.0" />
        <vers num="9.0.3.2.0" />
        <vers num="9.0.3.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1184" published="2003-11-03" name="CVE-2003-1184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13582" source="XF" patch="1" adv="1">thwboard-multiple-fields-xss(13582)</ref>
      <ref url="http://www.securityfocus.com/bid/8959" source="BID" patch="1">8959</ref>
      <ref url="http://www.osvdb.org/4829" source="OSVDB" patch="1" adv="1">4829</ref>
      <ref url="http://www.osvdb.org/4828" source="OSVDB" patch="1" adv="1">4828</ref>
      <ref url="http://www.osvdb.org/4827" source="OSVDB" patch="1" adv="1">4827</ref>
      <ref url="http://www.osvdb.org/4826" source="OSVDB" patch="1" adv="1">4826</ref>
      <ref url="http://www.osvdb.org/4825" source="OSVDB" patch="1" adv="1">4825</ref>
      <ref url="http://www.osvdb.org/3077" source="OSVDB" patch="1" adv="1">3077</ref>
      <ref url="http://secunia.com/advisories/10120" source="SECUNIA" patch="1" adv="1">10120</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=195009" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=195009</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1185" published="2003-11-03" name="CVE-2003-1185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13583" source="XF" patch="1" adv="1">thwboard-multiple-sql-injection(13583)</ref>
      <ref url="http://www.securityfocus.com/bid/8961" source="BID" patch="1">8961</ref>
      <ref url="http://www.osvdb.org/4841" source="OSVDB" patch="1" adv="1">4841</ref>
      <ref url="http://www.osvdb.org/4840" source="OSVDB" patch="1" adv="1">4840</ref>
      <ref url="http://www.osvdb.org/4838" source="OSVDB" patch="1" adv="1">4838</ref>
      <ref url="http://secunia.com/advisories/10120" source="SECUNIA" patch="1" adv="1">10120</ref>
      <ref url="http://www.osvdb.org/2758" source="OSVDB">2758</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=195009" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=195009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thwboard" name="thwboard">
        <vers num="2.81_beta" />
        <vers num="2.8_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1186" published="2003-10-29" name="CVE-2003-1186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 2.13.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8925" source="BID" patch="1">8925</ref>
      <ref url="http://www.securityfocus.com/archive/1/342785" source="BUGTRAQ" patch="1">20031029 TelCondex SimpleWebserver Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13549" source="XF" adv="1">simplewebserver-referer-bo(13549)</ref>
      <ref url="http://www.osvdb.org/10101" source="OSVDB">10101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telcondex" name="simplewebserver">
        <vers num="2.12.30210_build3285" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1187" published="2003-11-02" name="CVE-2003-1187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13590" source="XF" adv="1">phpkit-include-xss(13590)</ref>
      <ref url="http://www.securityfocus.com/bid/8960" source="BID">8960</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013139.html" source="FULLDISC" adv="1">20031102 [bWM#017] Cross-Site-Scripting @ PHPKIT</ref>
      <ref url="http://badwebmasters.net/advisory/017/" source="MISC" adv="1">http://badwebmasters.net/advisory/017/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.02" />
        <vers num="1.6.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1188" published="2003-11-02" name="CVE-2003-1188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13610" source="XF" adv="1">unichat-nonalphanumeric-character-dos(13610)</ref>
      <ref url="http://www.securityfocus.com/bid/8962" source="BID">8962</ref>
      <ref url="http://www.securityfocus.com/archive/1/343182" source="BUGTRAQ">20031102 Unichat Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/2844" source="OSVDB" adv="1">2844</ref>
      <ref url="http://secunia.com/advisories/10163" source="SECUNIA" adv="1">10163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unichat" name="unichat">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1189" published="2003-10-29" name="CVE-2003-1189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13539" source="XF" patch="1">nokia-ipso-ipcluster-dos(13539)</ref>
      <ref url="http://www.securityfocus.com/bid/8928" source="BID" patch="1">8928</ref>
      <ref url="http://securitytracker.com/id?1007992" source="SECTRACK" patch="1">1007992</ref>
      <ref url="http://secunia.com/advisories/10083" source="SECUNIA" patch="1">10083</ref>
      <ref url="http://www.osvdb.org/2724" source="OSVDB">2724</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="ipso">
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1190" published="2003-11-03" name="CVE-2003-1190" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in PHPRecipeBook 2.18.</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13574" source="XF" patch="1">phprecipebook-recipe-xss(13574)</ref>
      <ref url="http://www.securityfocus.com/bid/8963" source="BID" patch="1">8963</ref>
      <ref url="http://secunia.com/advisories/10109" source="SECUNIA" patch="1">10109</ref>
      <ref url="http://www.osvdb.org/2755" source="OSVDB" adv="1">2755</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=193940" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=193940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprecipebook" name="phprecipebook">
        <vers num="1.24" />
        <vers num="1.25" />
        <vers num="1.26" />
        <vers num="1.26a" />
        <vers num="1.27" />
        <vers num="1.27a" />
        <vers num="1.30" />
        <vers num="1.30a" />
        <vers num="1.31" />
        <vers num="2.04" />
        <vers num="2.05" />
        <vers num="2.06" />
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1191" published="2003-10-29" name="CVE-2003-1191" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8930" source="BID" patch="1">8930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13553" source="XF" adv="1">e107chatboxdos(13553)</ref>
      <ref url="http://www.osvdb.org/2753" source="OSVDB" adv="1">2753</ref>
      <ref url="http://secunia.com/advisories/10115" source="SECUNIA" adv="1">10115</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0313.html" source="BUGTRAQ">20031029 E107 DoS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.603" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1192" published="2003-11-03" name="CVE-2003-1192" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13580" source="XF" adv="1">iawebmailserver-get-bo(13580)</ref>
      <ref url="http://www.securityfocus.com/bid/8965" source="BID">8965</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6B002158UQ.html" source="MISC">http://www.securiteam.com/windowsntfocus/6B002158UQ.html</ref>
      <ref url="http://www.osvdb.org/2757" source="OSVDB" adv="1">2757</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2003-11/0001.html" source="VULNWATCH">20031103 IA WebMail Server 3.x Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1008075" source="SECTRACK">1008075</ref>
      <ref url="http://secunia.com/advisories/10107" source="SECUNIA" adv="1">10107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truenorth_software" name="ia_webmail_server">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1193" published="2003-11-03" name="CVE-2003-1193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/343520" source="BUGTRAQ" patch="1" adv="1">20031105 Multiple SQL Injection Vulnerabilities in Oracle Application Server 9i and RDBMS (#NISR05112003)</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf" source="CONFIRM" patch="1">http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13593" source="XF" adv="1">oracle-portal-sql-injection(13593)</ref>
      <ref url="http://www.securityfocus.com/bid/8966" source="BID" adv="1">8966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_portal">
        <vers num="3.0.9.8.5" />
        <vers num="9.0.2.3" />
        <vers num="9.0.2.3a" />
        <vers num="9.0.2.3b" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1194" published="2003-10-30" name="CVE-2003-1194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 0.2.4.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8932" source="BID" patch="1">8932</ref>
      <ref url="http://securitytracker.com/id?1008056" source="SECTRACK" patch="1">1008056</ref>
      <ref url="http://secunia.com/advisories/10110" source="SECUNIA" patch="1">10110</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13557" source="XF">booby-error-message-xss(13557)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=193878" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=193878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="booby" name="booby">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1195" published="2003-11-23" name="CVE-2003-1195" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/4606" source="OSVDB" patch="1">4606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13819" source="XF" adv="1">vieboard-getmember-sql-injection(13819)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014065.html" source="FULLDISC">20031123 VieNuke VieBoard SQL Injection Vulnerability... again</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1196" published="2003-11-03" name="CVE-2003-1196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8967" source="BID" patch="1">8967</ref>
      <ref url="http://www.osvdb.org/2789" source="OSVDB" patch="1">2789</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13629" source="XF" adv="1">vieboard-viewtopic-sql-injection(13629)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vienuke" name="vieboard">
        <vers num="2.6" />
        <vers num="2.6_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1197" published="2003-10-30" name="CVE-2003-1197" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13563" source="XF" adv="1">ledforums-topicfield-redirect(13563)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13562" source="XF" adv="1">ledforums-indexphp-xss(13562)</ref>
      <ref url="http://www.securityfocus.com/bid/8934" source="BID">8934</ref>
      <ref url="http://www.securityfocus.com/archive/1/342913" source="BUGTRAQ" adv="1">20031030 Multiple Vulnerabilities in Led-Forums</ref>
      <ref url="http://secunia.com/advisories/10113" source="SECUNIA">10113</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1198" published="2003-12-26" name="CVE-2003-1198" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 0.4.6-20040101.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9345" source="BID" patch="1">9345</ref>
      <ref url="http://secunia.com/advisories/10518" source="SECUNIA" patch="1">10518</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14119" source="XF" adv="1">cherokee-post-request-dos(14119)</ref>
      <ref url="http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog" source="CONFIRM" adv="1">http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cherokee" name="cherokee_httpd">
        <vers num="0.1" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.2" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1199" published="2004-03-11" name="CVE-2003-1199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15438" source="XF" adv="1">myproxy-xss(15438)</ref>
      <ref url="http://www.securityfocus.com/bid/9846" source="BID" adv="1">9846</ref>
      <ref url="http://www.osvdb.org/4202" source="OSVDB" adv="1">4202</ref>
      <ref url="http://secunia.com/advisories/11090" source="SECUNIA" adv="1">11090</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107902444305344&amp;w=2" source="BUGTRAQ" adv="1">20030311 XSS in MyProxy 20030629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myproxy" name="myproxy">
        <vers num="2003-06-29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1200" published="2003-12-29" name="CVE-2003-1200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14097" source="XF">mdaemon-form2raw-from-bo(14097)</ref>
      <ref url="http://www.securityfocus.com/bid/9317" source="BID" adv="1">9317</ref>
      <ref url="http://www.securityfocus.com/archive/1/348454" source="BUGTRAQ" adv="1">20031229 [Hat-Squad] Remote buffer overflow in Mdaemon Raw message Handler</ref>
      <ref url="http://www.osvdb.org/3255" source="OSVDB" adv="1">3255</ref>
      <ref url="http://secunia.com/advisories/10512" source="SECUNIA" adv="1">10512</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936753929354&amp;w=2" source="BUGTRAQ" adv="1">20040314 Rosiello Security's exploit for MDaemon</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="6.5.2" />
        <vers num="6.7.5" />
        <vers num="6.7.9" />
        <vers num="6.8.0" />
        <vers num="6.8.1" />
        <vers num="6.8.2" />
        <vers num="6.8.3" />
        <vers num="6.8.4" />
        <vers num="6.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1201" published="2003-03-20" name="CVE-2003-1201" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in OpenLDAP version 2.1.17.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7656" source="BID" patch="1">7656</ref>
      <ref url="http://www.openldap.org/its/index.cgi?findid=2390" source="CONFIRM" patch="1">http://www.openldap.org/its/index.cgi?findid=2390</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-12.xml" source="GENTOO" patch="1">GLSA-200403-12</ref>
      <ref url="http://secunia.com/advisories/9203" source="SECUNIA" patch="1">9203</ref>
      <ref url="http://secunia.com/advisories/11261" source="SECUNIA" patch="1">11261</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000685" source="CONECTIVA" patch="1">CLSA-2003:685</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12520" source="XF" adv="1">openldap-back-ldbm-dos(12520)</ref>
      <ref url="http://www.osvdb.org/17000" source="OSVDB">17000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.11_11" />
        <vers num="2.0.11_11s" />
        <vers num="2.0.11_9" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.25" />
        <vers num="2.0.27" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.13" />
        <vers num="2.1.14" />
        <vers num="2.1.15" />
        <vers num="2.1.16" />
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1202" published="2003-08-19" name="CVE-2003-1202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in version 0.98.5. However, there is a report that version 0.98.5 is still affected by this vulnerability.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8451" source="BID" patch="1">8451</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106149679129042&amp;w=2" source="BUGTRAQ" patch="1">20030821 Re: Remote Execution of Commands in Omail Webmail 0.98.4 and earlier</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106132514828641&amp;w=2" source="BUGTRAQ" patch="1">20030821 Remote Execution of Commands in Omail Webmail 0.98.4 and earlier</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12948" source="XF" adv="1">omailwebmail-checklogin-code-execution(12948)</ref>
      <ref url="http://secunia.com/advisories/9585" source="SECUNIA" adv="1">9585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omail" name="omail_webmail">
        <vers num="0.97.3" />
        <vers num="0.98.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1203" published="2003-03-18" name="CVE-2003-1203" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11601" source="XF" adv="1">mambo-option-index-xss(11601)</ref>
      <ref url="http://www.securityfocus.com/bid/7135" source="BID">7135</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html" source="BUGTRAQ">20030318 Some XSS vulns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_site_server">
        <vers num="4.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1204" published="2003-12-31" name="CVE-2003-1204" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.12 BETA and earlier allow remote attackers to execute script on other clients via (1) the link parameter in sectionswindow.php, the directory parameter in (2) gallery.php, (3) navigation.php, or (4) uploadimage.php, the path parameter in (5) view.php, (6) the choice parameter in upload.php, (7) the sitename parameter in mambosimple.php, (8) the type parameter in upload.php, or the id parameter in (9) emailarticle.php, (10) emailfaq.php, or (11) emailnews.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11050" source="XF">mambo-multiple-scripts-xss(11050)</ref>
      <ref url="http://www.securityfocus.com/bid/6571" source="BID">6571</ref>
      <ref url="http://www.securityfocus.com/archive/1/306206" source="BUGTRAQ">20030110 Mambo Site Server Remote Code Execution</ref>
      <ref url="http://www.osvdb.org/7505" source="OSVDB">7505</ref>
      <ref url="http://www.osvdb.org/7504" source="OSVDB">7504</ref>
      <ref url="http://www.osvdb.org/7503" source="OSVDB">7503</ref>
      <ref url="http://www.osvdb.org/7502" source="OSVDB">7502</ref>
      <ref url="http://www.osvdb.org/7501" source="OSVDB">7501</ref>
      <ref url="http://www.osvdb.org/7500" source="OSVDB">7500</ref>
      <ref url="http://www.osvdb.org/7499" source="OSVDB">7499</ref>
      <ref url="http://www.osvdb.org/7498" source="OSVDB">7498</ref>
      <ref url="http://www.osvdb.org/7497" source="OSVDB">7497</ref>
      <ref url="http://www.osvdb.org/7496" source="OSVDB">7496</ref>
      <ref url="http://www.osvdb.org/7495" source="OSVDB">7495</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1205" published="2003-08-06" name="CVE-2003-1205" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/9467" source="SECUNIA" patch="1">9467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12838" source="XF" adv="1">crob-rename-file-dos(12838)</ref>
      <ref url="http://www.osvdb.org/2378" source="OSVDB">2378</ref>
      <ref url="http://www.crob.net/studio/ftpserver/" source="MISC">http://www.crob.net/studio/ftpserver/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106019292611151&amp;w=2" source="BUGTRAQ">20030806 DoS Vulnerabilities in Crob FTP Server 2.60.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crob" name="crob_ftp_server">
        <vers num="2.60.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1206" published="2003-06-03" name="CVE-2003-1206" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/8929" source="SECUNIA" patch="1" adv="1">8929</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12834" source="XF" adv="1">crob-login-dos(12834)</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-08/0087.html" source="BUGTRAQ">20030807 Re: DoS Vulnerabilities in Crob FTP Server 2.60.1</ref>
      <ref url="http://www.crob.net/studio/ftpserver/" source="MISC">http://www.crob.net/studio/ftpserver/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106019292611151&amp;w=2" source="BUGTRAQ">20030806 DoS Vulnerabilities in Crob FTP Server 2.60.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crob" name="crob_ftp_server">
        <vers num="2.60.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1207" published="2004-02-01" name="CVE-2003-1207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9549" source="BID">9549</ref>
      <ref url="http://www.securityfocus.com/archive/1/352329" source="BUGTRAQ">20040201 Vulnerabilities in Crob FTP Server V3.5.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15105" source="XF">crob-dir-dos(15105)</ref>
      <ref url="http://securitytracker.com/id?1008908" source="SECTRACK">1008908</ref>
      <ref url="http://secunia.com/advisories/10778" source="SECUNIA">10778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crob" name="crob_ftp_server">
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1208" published="2004-12-03" name="CVE-2003-1208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in Oracle 9i Database Release 2, version 9.2.0.3.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/846582" source="CERT-VN" patch="1" adv="1">VU#846582</ref>
      <ref url="http://www.kb.cert.org/vuls/id/819126" source="CERT-VN" patch="1" adv="1">VU#819126</ref>
      <ref url="http://www.kb.cert.org/vuls/id/399806" source="CERT-VN" patch="1" adv="1">VU#399806</ref>
      <ref url="http://www.kb.cert.org/vuls/id/240174" source="CERT-VN" patch="1" adv="1">VU#240174</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15060" source="XF" patch="1" adv="1">oracle-multiple-function-bo(15060)</ref>
      <ref url="http://www.securityfocus.com/bid/9587" source="BID" patch="1" adv="1">9587</ref>
      <ref url="http://www.osvdb.org/3840" source="OSVDB" patch="1" adv="1">3840</ref>
      <ref url="http://www.osvdb.org/3839" source="OSVDB" patch="1" adv="1">3839</ref>
      <ref url="http://www.osvdb.org/3838" source="OSVDB" patch="1" adv="1">3838</ref>
      <ref url="http://www.osvdb.org/3837" source="OSVDB" patch="1" adv="1">3837</ref>
      <ref url="http://www.nextgenss.com/advisories/ora_numtoyminterval.txt" source="MISC" patch="1">http://www.nextgenss.com/advisories/ora_numtoyminterval.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/ora_numtodsinterval.txt" source="MISC" patch="1">http://www.nextgenss.com/advisories/ora_numtodsinterval.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/ora_from_tz.txt" source="MISC" patch="1">http://www.nextgenss.com/advisories/ora_from_tz.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-093.shtml" source="CIAC" patch="1" adv="1">O-093</ref>
      <ref url="http://secunia.com/advisories/10805" source="SECUNIA" patch="1">10805</ref>
      <ref url="http://www.nextgenss.com/advisories/ora_time_zone.txt" source="MISC">http://www.nextgenss.com/advisories/ora_time_zone.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html" source="BUGTRAQ" adv="1">20040205 Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1209" published="2003-12-31" name="CVE-2003-1209" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7201" source="BID" patch="1">7201</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11650" source="XF">monkey-content-type-dos(11650)</ref>
      <ref url="http://monkeyd.sourceforge.net/Changelog.txt" source="CONFIRM">http://monkeyd.sourceforge.net/Changelog.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey" name="monkey_http_daemon">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1210" published="2003-12-31" name="CVE-2003-1210" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11984" source="XF">phpnuke-multiple-sql-injection(11984)</ref>
      <ref url="http://www.securityfocus.com/bid/7588" source="BID">7588</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html" source="BUGTRAQ">20030513 More and More SQL injection on PHP-Nuke 6.5.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1211" published="2003-12-31" name="CVE-2003-1211" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7837" source="BID" patch="1">7837</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" source="BUGTRAQ" patch="1">20030606 Critical Vulnerabilities In Max Web Portal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12277" source="XF">maxwebportal-search-xss(12277)</ref>
      <ref url="http://www.osvdb.org/3281" source="OSVDB">3281</ref>
      <ref url="http://secunia.com/advisories/8979" source="SECUNIA">8979</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1212" published="2003-12-31" name="CVE-2003-1212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7837" source="BID" patch="1">7837</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" source="BUGTRAQ" patch="1">20030606 Critical Vulnerabilities In Max Web Portal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12278" source="XF">maxwebportal-form-field-modify(12278)</ref>
      <ref url="http://www.osvdb.org/4933" source="OSVDB">4933</ref>
      <ref url="http://secunia.com/advisories/8979" source="SECUNIA">8979</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1213" published="2003-12-31" name="CVE-2003-1213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7837" source="BID" patch="1">7837</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" source="BUGTRAQ" patch="1">20030606 Critical Vulnerabilities In Max Web Portal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12279" source="XF">maxwebportal-database-access(12279)</ref>
      <ref url="http://secunia.com/advisories/8979" source="SECUNIA">8979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1214" published="2004-02-11" name="CVE-2003-1214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ezcontents.org/forum/viewtopic.php?t=361" source="CONFIRM" patch="1">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref>
      <ref url="http://secunia.com/advisories/10839" source="SECUNIA" patch="1">10839</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15136" source="XF">ezcontents-login-bypass(15136)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualshapers" name="ezcontents">
        <vers num="1.40" />
        <vers num="1.41" />
        <vers num="1.42" />
        <vers num="1.43" />
        <vers num="1.44" />
        <vers num="1.45" />
        <vers num="1.45b" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1215" published="2003-12-29" name="CVE-2003-1215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9314" source="BID" patch="1" adv="1">9314</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107273069130885&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031229 SQL Injection in phpBB's groupcp.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14096" source="XF" adv="1">phpbb-groupcp-sql-injection(14096)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1216" published="2003-11-27" name="CVE-2003-1216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13867" source="XF" patch="1" adv="1">phpbb-searchphp-sql-injection(13867)</ref>
      <ref url="http://www.securityfocus.com/bid/9122" source="BID" patch="1" adv="1">9122</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?t=153818" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=153818</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107196735102970&amp;w=2" source="BUGTRAQ" adv="1">20031220 phpBB v2.06 search_id sql injection exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107005608726609&amp;w=2" source="BUGTRAQ" adv="1">20031128 [Hat-Squad] phpBB search_id injection exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106997132425576&amp;w=2" source="BUGTRAQ" adv="1">20031127 phpBB 2.06 search.php SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1219" published="2003-12-31" name="CVE-2003-1219" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9238" source="BID">9238</ref>
      <ref url="http://www.securityfocus.com/archive/1/347831" source="BUGTRAQ">20031217 osCommerce Malformed Session ID XSS Vuln</ref>
      <ref url="http://www.oscommerce.com/community/bugs,1546" source="CONFIRM">http://www.oscommerce.com/community/bugs,1546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers prev="1" num="2.2_ms2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1220" published="2003-12-31" name="CVE-2003-1220" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9034" source="BID" patch="1">9034</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/25" source="BEA">BEA03-39.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1221" published="2003-12-31" name="CVE-2003-1221" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9034" source="BID" patch="1">9034</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/32" source="BEA">BEA03-40.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1222" published="2003-12-31" name="CVE-2003-1222" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9034" source="BID" patch="1">9034</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/63" source="BEA">BEA03-41.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1223" published="2003-12-31" name="CVE-2003-1223" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9034" source="BID" patch="1">9034</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/48" source="BEA">BEA03-42.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1224" published="2003-12-31" name="CVE-2003-1224" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7563" source="BID" patch="1">7563</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/22" source="BEA">BEA03-30.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1225" published="2003-12-31" name="CVE-2003-1225" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7563" source="BID" patch="1">7563</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/22" source="BEA">BEA03-30.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1226" published="2003-12-31" name="CVE-2003-1226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7587" source="BID" patch="1">7587</ref>
      <ref url="http://www.securityfocus.com/bid/7563" source="BID" patch="1">7563</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/22" source="BEA">BEA03-30.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1227" published="2003-12-31" name="CVE-2003-1227" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.  NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8814" source="BID" patch="1">8814</ref>
      <ref url="http://www.securityfocus.com/archive/1/341044" source="BUGTRAQ" patch="1" adv="1">20031011 Gallery 1.4 including file vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13419" source="XF">gallery-indexphp-file-include(13419)</ref>
      <ref url="http://www.securityfocus.com/archive/1/341098" source="BUGTRAQ">20031012 Re: Gallery 1.4 including file vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/341094" source="BUGTRAQ">20031011 RE: Gallery 1.4 including file vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4" />
        <vers num="1.4_pl1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1228" published="2003-12-31" name="CVE-2003-1228" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15474" source="XF" patch="1">mathopd-preparereply-bo(15474)</ref>
      <ref url="http://www.securityfocus.com/bid/9871" source="BID" patch="1">9871</ref>
      <ref url="http://www.securiteam.com/unixfocus/5FP0C1FCAW.html" source="MISC" patch="1">http://www.securiteam.com/unixfocus/5FP0C1FCAW.html</ref>
      <ref url="http://secunia.com/advisories/10385/" source="SECUNIA" patch="1" adv="1">10385</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107090601705839&amp;w=2" source="BUGTRAQ">20031208 Re: [Fwd: Security Alert; possible buffer overflow in all Mathopd</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107064887507504&amp;w=2" source="BUGTRAQ">20031205 [Fwd: Security Alert; possible buffer overflow in all Mathopd versions]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mathopd" name="mathopd">
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3_p17" />
        <vers num="1.3_p18" />
        <vers num="1.3_p4" />
        <vers num="1.3_p5" />
        <vers num="1.3_p6" />
        <vers num="1.3_p7" />
        <vers num="1.3_p8" />
        <vers num="1.4" />
        <vers num="1.4_p1" />
        <vers num="1.5_b13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1229" published="2003-12-31" name="CVE-2003-1229" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11182" source="XF" patch="1">sun-java-improper-validation(11182)</ref>
      <ref url="http://www.securityfocus.com/bid/6682" source="BID" patch="1">6682</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1" source="SUNALERT" patch="1" adv="1">50081</ref>
      <ref url="http://secunia.com/advisories/7943" source="SECUNIA" patch="1" adv="1">7943</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0301-239" source="HP">HPSBUX0301-239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5883" source="OVAL">oval:org.mitre.oval:def:5883</ref>
      <ref url="http://java.sun.com/products/jsse/CHANGES.txt" source="CONFIRM">http://java.sun.com/products/jsse/CHANGES.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0334.html" source="BUGTRAQ">20030128 Incorrect Certificate Validation in Java Secure Socket Extension</ref>
      <ref url="http://www.securitytracker.com/id?1006001" source="SECTRACK">1006001</ref>
      <ref url="http://securitytracker.com/id?1007483" source="SECTRACK">1007483</ref>
      <ref url="http://securitytracker.com/id?1006007" source="SECTRACK">1006007</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1230" published="2003-12-31" name="CVE-2003-1230" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11397" source="XF" patch="1">freebsd-syncookie-brute-force(11397)</ref>
      <ref url="http://www.securityfocus.com/bid/6920" source="BID" patch="1">6920</ref>
      <ref url="http://www.securityfocus.com/advisories/5013" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-03:03</ref>
      <ref url="http://secunia.com/advisories/8142/" source="SECUNIA" adv="1">8142</ref>
      <ref url="http://www.osvdb.org/19785" source="OSVDB">19785</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1231" published="2003-12-31" name="CVE-2003-1231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14032" source="XF">ecwshop-cat-xss(14032)</ref>
      <ref url="http://www.securityfocus.com/bid/9244" source="BID">9244</ref>
      <ref url="http://www.securiteam.com/unixfocus/6D00F2A95C.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/6D00F2A95C.html</ref>
      <ref url="http://securitytracker.com/id?1008522" source="SECTRACK">1008522</ref>
      <ref url="http://secunia.com/advisories/10458" source="SECUNIA" adv="1">10458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecw-shop" name="ecw-shop">
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1232" published="2003-12-31" name="CVE-2003-1232" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html" source="MISC" patch="1">http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html</ref>
      <ref url="http://secunia.com/advisories/17496" source="SECUNIA">17496</ref>
      <ref url="http://groups.google.com/group/gnu.emacs.bug/browse_frm/thread/9424ec1b2fdae321/c691a2da8904db0f?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;rnum=1&amp;prev=/groups%3Fq%3Dguninski%2Bemacs%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3Dmailman.763.1041357806.19936.bug-gnu-emacs%2540gnu.org%26rnum%3D1#c691a2da8904db0f" source="MISC">http://groups.google.com/group/gnu.emacs.bug/browse_frm/thread/9424ec1b2fdae321/c691a2da8904db0f?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;rnum=1&amp;prev=/groups%3Fq%3Dguninski%2Bemacs%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3Dmailman.763.1041357806.19936.bug-gnu-emacs%2540gnu.org%26rnum%3D1#c691a2da8904db0f</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183</ref>
      <ref url="http://www.securityfocus.com/bid/15375" source="BID">15375</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:208" source="MANDRIVA">MDKSA-2005:208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers num="21.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1233" published="2003-12-31" name="CVE-2003-1233" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/10979" source="XF" patch="1">ipd-ntcreatesymboliclinkobject-subs-symlink(10979)</ref>
      <ref url="http://www.securityfocus.com/bid/6511" source="BID" patch="1">6511</ref>
      <ref url="http://secunia.com/advisories/7816" source="SECUNIA" patch="1" adv="1">7816</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html" source="BUGTRAQ" patch="1">20030103 Another way to bypass Integrity Protection Driver ('subst' vuln)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html" source="BUGTRAQ" patch="1">20030103 Pedestal Software Security Notice</ref>
      <ref url="http://www.phrack.org/show.php?p=59&amp;a=16" source="MISC">http://www.phrack.org/show.php?p=59&amp;a=16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pedestal_software" name="integrity_protection_driver">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1234" published="2003-12-31" name="CVE-2003-1234" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6524" source="BID" patch="1">6524</ref>
      <ref url="http://www.iss.net/security_center/static/10993.php" source="XF" patch="1">freebsd-kernel-integer-overflow(10993)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0057.html" source="BUGTRAQ" patch="1">20030107 FreeBSD Security Advisory FreeBSD-SA-02:44.filedesc</ref>
      <ref url="http://www.pine.nl/press/pine-cert-20030101.txt" source="MISC">http://www.pine.nl/press/pine-cert-20030101.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0006.html" source="VULNWATCH">20030106 PDS: Integer overflow in FreeBSD kernel</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:44.filedesc.asc" source="FREEBSD" adv="1">FreeBSD-SA-02:44</ref>
      <ref url="http://www.securitytracker.com/id?1005898" source="SECTRACK">1005898</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/305308/30/26420/threaded" source="BUGTRAQ">20030106 PDS: Integer overflow in FreeBSD kernel</ref>
      <ref url="http://secunia.com/advisories/7821" source="SECUNIA">7821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7" />
        <vers num="2.1.7.1" />
        <vers num="2.2" edition="current" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.1" edition="release" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="release_p8" />
        <vers num="4.10" edition="releng" />
        <vers num="4.11" edition="release_p3" />
        <vers num="4.11" edition="releng" />
        <vers num="4.11" edition="stable" />
        <vers num="4.2" />
        <vers num="4.3" edition="release" />
        <vers num="4.4" />
        <vers num="4.5" edition="release" />
        <vers num="4.6" edition="release" />
        <vers num="4.7" edition="release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1235" published="2003-12-31" name="CVE-2003-1235" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current working directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7283" source="BID">7283</ref>
      <ref url="http://www.iss.net/security_center/static/11686.php" source="XF">webweaver-testcgi-info-disclosure(11686)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0014.html" source="BUGTRAQ">20030331 BRS WebWeaver: full disclosure</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1236" published="2003-12-31" name="CVE-2003-1236" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6553" source="BID" patch="1">6553</ref>
      <ref url="http://www.securityfocus.com/archive/1/305460" source="BUGTRAQ" patch="1">20030107 [INetCop Security Advisory] Remote format string vulnerability in    Tanne.</ref>
      <ref url="http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2" source="CONFIRM" patch="1">http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0011.html" source="VULNWATCH" patch="1">20030107 [INetCop Security Advisory] Remote format string vulnerability in Tanne.</ref>
      <ref url="http://www.securityfocus.com/archive/1/305663" source="BUGTRAQ">20030108 Tanne Remote format string exploit (Proof of Concept)</ref>
      <ref url="http://www.iss.net/security_center/static/11006.php" source="XF">tanne-logger-format-string(11006)</ref>
      <ref url="http://www.securitytracker.com/id?1005900" source="SECTRACK">1005900</ref>
      <ref url="http://secunia.com/advisories/7831" source="SECUNIA">7831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tanne" name="tanne">
        <vers num="0.6.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1237" published="2003-12-31" name="CVE-2003-1237" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6918" source="BID">6918</ref>
      <ref url="http://www.iss.net/security_center/static/11383.php" source="XF">wwwboard-message-xss(11383)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0274.html" source="BUGTRAQ">20030222 [SCSA-007] Cross Site Scripting Vulnerabilities in WWWBoard</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1238" published="2003-12-31" name="CVE-2003-1238" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6916" source="BID">6916</ref>
      <ref url="http://www.iss.net/security_center/static/11420.php" source="XF">nuked-klan-team-xss(11420)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html" source="BUGTRAQ">20030318 Some XSS vulns</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html" source="BUGTRAQ">20030221 [SCSA-006] XSS &amp; Function Execution Vulnerabilities in Nuked-Klan</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers num="1.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1239" published="2003-12-31" name="CVE-2003-1239" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6929" source="BID" patch="1">6929</ref>
      <ref url="http://www.securityfocus.com/archive/1/312966" source="BUGTRAQ" patch="1">20030223 WihPhoto (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html" source="VULNWATCH" patch="1">20030223 WihPhoto (PHP)</ref>
      <ref url="http://www.iss.net/security_center/static/11429.php" source="XF">wihphoto-sendphoto-file-disclosure(11429)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wihphoto" name="wihphoto">
        <vers num="0.86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1240" published="2003-12-31" name="CVE-2003-1240" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6935" source="BID">6935</ref>
      <ref url="http://www.iss.net/security_center/static/11417.php" source="XF">cutenews-php-file-include(11417)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0320.html" source="BUGTRAQ">20030225 PHP code injection in CuteNews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="0.88" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1241" published="2003-12-31" name="CVE-2003-1241" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/312762" source="BUGTRAQ" patch="1" adv="1">20030221 Myguestbook (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0089.html" source="VULNWATCH" patch="1" adv="1">20030221 Myguestbook (PHP)</ref>
      <ref url="http://www.securityfocus.com/bid/6906" source="BID">6906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="levcgi.com" name="myguestbook">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1242" published="2003-12-31" name="CVE-2003-1242" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6893" source="BID">6893</ref>
      <ref url="http://www.iss.net/security_center/static/11372.php" source="XF">sage-module-path-disclosure(11372)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0236.html" source="BUGTRAQ" adv="1">20030219 XSS and Path Disclosure in Sage</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1243" published="2003-12-31" name="CVE-2003-1243" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11371" source="XF">sage-mod-xss(11371)</ref>
      <ref url="http://www.securityfocus.com/bid/6894" source="BID">6894</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0236.html" source="BUGTRAQ" adv="1">20030219 XSS and Path Disclosure in Sage</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1244" published="2003-12-31" name="CVE-2003-1244" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6888" source="BID" patch="1">6888</ref>
      <ref url="http://www.iss.net/security_center/static/11376.php" source="XF" patch="1">phpbb-pageheader-sql-injection(11376)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0245.html" source="BUGTRAQ" adv="1">20030220 phpBB Security Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1245" published="2003-12-31" name="CVE-2003-1245" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6926" source="BID" patch="1">6926</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11398" source="XF">mambo-sessionid-gain-privileges(11398)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0302.html" source="BUGTRAQ" adv="1">20030224 Mambo SiteServer exploit gains administrative privileges</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1246" published="2003-12-31" name="CVE-2003-1246" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6511" source="BID" patch="1">6511</ref>
      <ref url="http://www.iss.net/security_center/static/10979.php" source="XF" patch="1">ipd-ntcreatesymboliclinkobject-subs-symlink(10979)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html" source="BUGTRAQ" patch="1" adv="1">20030103 Another way to bypass Integrity Protection Driver ('subst' vuln)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html" source="BUGTRAQ" patch="1" adv="1">20030103 Pedestal Software Security Notice</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pedestal_software" name="integrity_protection_driver">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1247" published="2003-12-31" name="CVE-2003-1247" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6540" source="BID" patch="1">6540</ref>
      <ref url="http://www.securityfocus.com/bid/6538" source="BID" patch="1">6538</ref>
      <ref url="http://www.securityfocus.com/bid/6537" source="BID" patch="1">6537</ref>
      <ref url="http://www.securityfocus.com/archive/1/305313" source="BUGTRAQ" patch="1" adv="1">20030106 Remote root vuln in HSphere WebShell</ref>
      <ref url="http://www.iss.net/security_center/static/11003.php" source="XF" patch="1">hsphere-webshell-flist-bo(11003)</ref>
      <ref url="http://www.iss.net/security_center/static/11002.php" source="XF" patch="1">hsphere-webshell-diskusage-bo(11002)</ref>
      <ref url="http://www.iss.net/security_center/static/10999.php" source="XF" patch="1">hsphere-webshell-readfile-bo(10999)</ref>
      <ref url="http://psoft.net/misc/webshell_patch.html" source="MISC" patch="1">http://psoft.net/misc/webshell_patch.html</ref>
      <ref url="http://www.securitytracker.com/id?1005893" source="SECTRACK">1005893</ref>
      <ref url="http://www.securityfocus.com/bid/6527" source="BID">6527</ref>
      <ref url="http://secunia.com/advisories/7832" source="SECUNIA">7832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="positive_software" name="h-sphere">
        <vers num="2.3_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1248" published="2003-12-31" name="CVE-2003-1248" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6539" source="BID" patch="1">6539</ref>
      <ref url="http://www.securityfocus.com/bid/6537" source="BID" patch="1">6537</ref>
      <ref url="http://www.securityfocus.com/archive/1/305313" source="BUGTRAQ" patch="1" adv="1">20030106 Remote root vuln in HSphere WebShell</ref>
      <ref url="http://www.iss.net/security_center/static/11001.php" source="XF" patch="1">hsphere-webshell-encodefilename-execution(11001)</ref>
      <ref url="http://psoft.net/misc/webshell_patch.html" source="MISC" patch="1">http://psoft.net/misc/webshell_patch.html</ref>
      <ref url="http://www.securitytracker.com/id?1005893" source="SECTRACK">1005893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="positive_software" name="h-sphere">
        <vers num="2.3_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1249" published="2003-12-31" name="CVE-2003-1249" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6569" source="BID" patch="1">6569</ref>
      <ref url="http://www.securityfocus.com/archive/1/305991" source="BUGTRAQ" patch="1" adv="1">20030109 WebIntelligence session hijacking vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0014.html" source="VULNWATCH" patch="1" adv="1">20030109 WebIntelligence session hijacking vulnerability</ref>
      <ref url="http://www.iss.net/security_center/static/11026.php" source="XF">webintelligence-session-hijacking(11026)</ref>
      <ref url="http://www.securitytracker.com/id?1005906" source="SECTRACK">1005906</ref>
      <ref url="http://secunia.com/advisories/7846" source="SECUNIA">7846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="businessobjects" name="webintelligence">
        <vers num="2.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1250" published="2003-12-31" name="CVE-2003-1250" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN packets to the WAN interface using a port scanner such as nmap.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6573" source="BID">6573</ref>
      <ref url="http://www.securityfocus.com/archive/1/308008" source="BUGTRAQ">20030123 5861 IP Filtering issues</ref>
      <ref url="http://www.securityfocus.com/archive/1/306081" source="BUGTRAQ" adv="1">20030110 Efficient Networks 5861 DSL Router</ref>
      <ref url="http://www.iss.net/security_center/static/11032.php" source="XF">efficient-dsl-portscan-dos(11032)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0015.html" source="VULNWATCH" adv="1">20030110 Efficient Networks 5861 DSL Router</ref>
      <ref url="http://www.securitytracker.com/id?1005910" source="SECTRACK">1005910</ref>
      <ref url="http://securitytracker.com/id?1005980" source="SECTRACK">1005980</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efficient_networks" name="5861_dsl_router">
        <vers num="5.3.80_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1251" published="2003-12-31" name="CVE-2003-1251" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0005.html" source="BUGTRAQ" patch="1">20030102 N/X (PHP)</ref>
      <ref url="http://www.securityfocus.com/bid/6500" source="BID">6500</ref>
      <ref url="http://www.iss.net/security_center/static/10969.php" source="XF">nx-file-include(10969)</ref>
      <ref url="http://secunia.com/advisories/7808" source="SECUNIA">7808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nx" name="n_x_web_content_management_system_2002">
        <vers num="prerelease1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1252" published="2003-12-31" name="CVE-2003-1252" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6547" source="BID">6547</ref>
      <ref url="http://www.securityfocus.com/archive/1/305406" source="BUGTRAQ" adv="1">20030105 A security vulnerability in S8Forum</ref>
      <ref url="http://www.iss.net/security_center/static/10974.php" source="XF">s8forum-register-command-execution(10974)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0004.html" source="VULNWATCH" adv="1">20030105 A security vulnerability in S8Forum</ref>
      <ref url="http://www.securitytracker.com/id?1005881" source="SECTRACK">1005881</ref>
      <ref url="http://secunia.com/advisories/7819" source="SECUNIA">7819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kelli_shaver" name="s8forum">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1253" published="2003-12-31" name="CVE-2003-1253" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11009.php" source="XF">bookmark4u-file-include(11009)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" source="BUGTRAQ" adv="1">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sangwan_kim" name="bookmark4u">
        <vers num="1.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1254" published="2003-12-31" name="CVE-2003-1254" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" source="BUGTRAQ" patch="1">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/6545" source="BID">6545</ref>
      <ref url="http://www.iss.net/security_center/static/11010.php" source="XF">apb-apbsettings-file-include(11010)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1255" published="2003-12-31" name="CVE-2003-1255" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11011" source="XF">apb-addbookmark-authentication-bypass(11011)</ref>
      <ref url="http://www.securityfocus.com/bid/6546" source="BID">6546</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" source="BUGTRAQ">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_php_bookmarks" name="active_php_bookmarks">
        <vers num="1.1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1256" published="2003-12-31" name="CVE-2003-1256" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/305381" source="BUGTRAQ" patch="1">20030106 E-theni (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.html" source="VULNWATCH" patch="1">20030106 E-theni (PHP)</ref>
      <ref url="http://www.securityfocus.com/bid/6970" source="BID">6970</ref>
      <ref url="http://www.iss.net/security_center/static/11013.php" source="XF">etheni-afflistelangue-file-include(11013)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-theni" name="e-theni">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1257" published="2003-12-31" name="CVE-2003-1257" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/305381" source="BUGTRAQ" patch="1">20030106 E-theni (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.html" source="VULNWATCH" patch="1">20030106 E-theni (PHP)</ref>
      <ref url="http://www.iss.net/security_center/static/11012.php" source="XF">etheni-findthenihome-information-disclosure(11012)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-theni" name="e-theni">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1258" published="2003-12-31" name="CVE-2003-1258" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0017.html" source="VULNWATCH" patch="1">20030110 vulnerability in versatile BulletinBoard  Allows Gaining Administrative Privileges.</ref>
      <ref url="http://www.iss.net/security_center/static/11044.php" source="XF">vbb-unauthorized-privileges(11044)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="versatilebulletinboard" name="versatilebulletinboard">
        <vers num="0.9.5" />
        <vers num="0.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1259" published="2003-12-31" name="CVE-2003-1259" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/325659" source="BUGTRAQ" patch="1">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/6518" source="BID">6518</ref>
      <ref url="http://www.iss.net/security_center/static/10984.php" source="XF">cuteftp-ftp-banner-bo(10984)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0026.html" source="BUGTRAQ" adv="1">20030104 CuteFTP: buffer overflow</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1260" published="2003-12-31" name="CVE-2003-1260" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/325659" source="BUGTRAQ" patch="1">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/6642" source="BID">6642</ref>
      <ref url="http://www.iss.net/security_center/static/11093.php" source="XF">cuteftp-list-command-bo(11093)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0123.html" source="BUGTRAQ">20030118 CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref url="http://www.osvdb.org/2181" source="OSVDB">2181</ref>
      <ref url="http://secunia.com/advisories/7898" source="SECUNIA">7898</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2003/Jan/0126.html" source="FULLDISC">20030107 CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0087.html" source="BUGTRAQ">20030205 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalscape" name="cuteftp">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1261" published="2003-12-31" name="CVE-2003-1261" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6786" source="BID" patch="1">6786</ref>
      <ref url="http://www.iss.net/security_center/static/11275.php" source="XF" patch="1">cuteftp-url-clipboard-bo(11275)</ref>
      <ref url="http://www.securityfocus.com/archive/1/310710" source="BUGTRAQ">20030206 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/325659" source="BUGTRAQ">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0087.html" source="BUGTRAQ">20030205 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalscape" name="cuteftp">
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1262" published="2003-12-31" name="CVE-2003-1262" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a long (1) host, (2) referer, or (3) userAgent value.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6531" source="BID" patch="1">6531</ref>
      <ref url="http://www.securityfocus.com/archive/1/305340" source="BUGTRAQ" patch="1">20030106 [INetCop Security Advisory] Buffer Overflow vulnerability in HTTP Fetcher Library.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104195613529429&amp;w=2" source="BUGTRAQ" patch="1">20030107 GLSA:  http-fetcher</ref>
      <ref url="http://www.iss.net/security_center/static/11000.php" source="XF">http-fetcher-httpfetch-bo(11000)</ref>
      <ref url="http://www.linuxsecurity.com/content/view/104480/104/" source="GENTOO">GLSA-200301-6</ref>
      <ref url="http://secunia.com/advisories/7823" source="SECUNIA">7823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="http_fetcher" name="http_fetcher_library">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1263" published="2003-12-31" name="CVE-2003-1263" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6506" source="BID" patch="1">6506</ref>
      <ref url="http://www.iss.net/security_center/static/10973.php" source="XF">ical-icalexe-port-dos(10973)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0011.html" source="BUGTRAQ" adv="1">20030103 ical 3.7 remote dos</ref>
      <ref url="http://www.securityfocus.com/bid/6505" source="BID">6505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brown_bear_software" name="ical">
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1264" published="2003-12-31" name="CVE-2003-1264" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6533" source="BID">6533</ref>
      <ref url="http://www.securityfocus.com/archive/1/305391" source="BUGTRAQ">20030106 Re: Longshine WLAN Access-Point LCS-883R VU#310201</ref>
      <ref url="http://www.securityfocus.com/archive/1/305344" source="BUGTRAQ">20030106 Longshine WLAN Access-Point LCS-883R VU#310201</ref>
      <ref url="http://www.iss.net/security_center/static/10997.php" source="XF">longshine-ap-tftp-access(10997)</ref>
      <ref url="http://www.securitytracker.com/id?1005897" source="SECTRACK">1005897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="di-614+">
        <vers num="2.0" />
      </prod>
      <prod vendor="longshine_technologie" name="longshine_wireless_ethernet_access_point">
        <vers num="lcs-883r-ac-b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1265" published="2003-12-31" name="CVE-2003-1265" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6499" source="BID">6499</ref>
      <ref url="http://www.iss.net/security_center/static/10963.php" source="XF">netscape-email-deletion-failure(10963)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2002-12/0277.html" source="BUGTRAQ" adv="1">20030101 Potential disclosure of sensitive information in Netscape 7.0 email client</ref>
      <ref url="http://www.securitytracker.com/id?1005871" source="SECTRACK">1005871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="5.0" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1266" published="2003-12-31" name="CVE-2003-1266" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6522" source="BID" patch="1">6522</ref>
      <ref url="http://www.securityfocus.com/bid/6521" source="BID" patch="1">6521</ref>
      <ref url="http://www.securityfocus.com/bid/6520" source="BID" patch="1">6520</ref>
      <ref url="http://www.securityfocus.com/bid/6519" source="BID" patch="1">6519</ref>
      <ref url="http://www.iss.net/security_center/static/10975.php" source="XF" patch="1">eserv-remote-data-dos(10975)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0022.html" source="BUGTRAQ" patch="1">20030104 EServ/2.97 remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etype" name="eserv">
        <vers num="2.92" />
        <vers num="2.93" />
        <vers num="2.94" />
        <vers num="2.95" />
        <vers num="2.96" />
        <vers num="2.97" />
        <vers num="2.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1267" published="2003-12-31" name="CVE-2003-1267" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/windowsntfocus/5SP030A8UO.html" source="MISC">http://www.securiteam.com/windowsntfocus/5SP030A8UO.html</ref>
      <ref url="http://www.iss.net/security_center/static/10964.php" source="XF">guildftpd-aux-port-dos(10964)</ref>
      <ref url="http://www.securitytracker.com/id?1005864" source="SECTRACK">1005864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steve_poulsen" name="guildftpd">
        <vers num="0.999" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1268" published="2003-12-31" name="CVE-2003-1268" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6558" source="BID">6558</ref>
      <ref url="http://www.securityfocus.com/archive/1/305685" source="BUGTRAQ" adv="1">20030108 a.shopKart Shopping Cart remote vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11029.php" source="XF">ashopkart-multiple-sql-injection(11029)</ref>
      <ref url="http://www.centaura.com.ar/infosec/adv/ashopkart.txt" source="MISC">http://www.centaura.com.ar/infosec/adv/ashopkart.txt</ref>
      <ref url="http://www.securitytracker.com/id?1005903" source="SECTRACK">1005903</ref>
      <ref url="http://www.osvdb.org/37038" source="OSVDB">37038</ref>
      <ref url="http://www.osvdb.org/37037" source="OSVDB">37037</ref>
      <ref url="http://www.osvdb.org/37036" source="OSVDB">37036</ref>
      <ref url="http://secunia.com/advisories/7838" source="SECUNIA">7838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="urlogy" name="a.shop.kart">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1269" published="2003-12-31" name="CVE-2003-1269" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6528" source="BID">6528</ref>
      <ref url="http://www.securityfocus.com/archive/1/305234" source="BUGTRAQ" adv="1">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</ref>
      <ref url="http://www.iss.net/security_center/static/10976.php" source="XF">an-http-path-disclosure(10976)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-http">
        <vers num="1.41e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1270" published="2003-12-31" name="CVE-2003-1270" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/305234" source="BUGTRAQ" adv="1">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</ref>
      <ref url="http://www.iss.net/security_center/static/10978.php" source="XF">an-http-script-dos(10978)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-http">
        <vers num="1.41e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1271" published="2003-12-31" name="CVE-2003-1271" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6529" source="BID" patch="1">6529</ref>
      <ref url="http://www.securityfocus.com/archive/1/305234" source="BUGTRAQ" adv="1">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</ref>
      <ref url="http://www.iss.net/security_center/static/10977.php" source="XF">an-http-script-xss(10977)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-http">
        <vers num="1.41e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1272" published="2003-12-31" name="CVE-2003-1272" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/10981" source="XF">winamp-b4s-path-bo(10981)</ref>
      <ref url="http://www.securityfocus.com/bid/6516" source="BID">6516</ref>
      <ref url="http://www.securityfocus.com/bid/6515" source="BID">6515</ref>
      <ref url="http://www.iss.net/security_center/static/10980.php" source="XF">winamp-b4s-playlistname-bo(10980)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" source="BUGTRAQ" adv="1">20030104 WinAmp v.3.0: buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1273" published="2003-12-31" name="CVE-2003-1273" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Winamp 3.0 allows remote attackers to cause a denial of service (crash) via a .b4s file with a playlist name that contains some non-English characters, e.g. Cyrillic characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/10982" source="XF">winamp-b4s-playlistname-dos(10982)</ref>
      <ref url="http://www.securityfocus.com/bid/6517" source="XF">6517</ref>
      <ref url="http://www.securityfocus.com/bid/6517" source="XF">6517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" source="BUGTRAQ" adv="1">20030104 WinAmp v.3.0: buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1274" published="2003-12-31" name="CVE-2003-1274" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/10983" source="XF">winamp-b4s-path-dos(10983)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" source="BUGTRAQ" adv="1">20030104 WinAmp v.3.0: buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1275" published="2003-12-31" name="CVE-2003-1275" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6507" source="BID">6507</ref>
      <ref url="http://www.iss.net/security_center/static/11004.php" source="XF">pie-javascript-objectinnerhtml-dos(11004)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0013.html" source="BUGTRAQ" adv="1">20030103 JS Bug makes it possible to deliberately crash Pocket PC IE</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="pocket_ie">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1276" published="2003-12-31" name="CVE-2003-1276" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry key, which could allow local users to gain unauthorized access to NetTelephone accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11007.php" source="XF">nettelephone-insecure-account-information(11007)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0046.html" source="BUGTRAQ" adv="1">20030103 Multiple Issues in Nettelephone Dialer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nettelephone" name="nettelephone">
        <vers num="3.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1277" published="2003-12-31" name="CVE-2003-1277" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5BP061F8US.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5BP061F8US.html</ref>
      <ref url="http://www.securiteam.com/unixfocus/5BP051F8VE.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5BP051F8VE.html</ref>
      <ref url="http://www.iss.net/security_center/static/10990.php" source="XF">yabb-se-index-xss(10990)</ref>
      <ref url="http://www.iss.net/security_center/static/10989.php" source="XF">yabb-newstemplate-xss(10989)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1278" published="2003-12-31" name="CVE-2003-1278" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6523" source="BID">6523</ref>
      <ref url="http://www.securityfocus.com/archive/1/305232" source="BUGTRAQ" adv="1">20030104 OpenTopic security hole</ref>
      <ref url="http://www.iss.net/security_center/static/10985.php" source="XF">opentopic-img-xss(10985)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopop" name="opentopic">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1279" published="2003-12-31" name="CVE-2003-1279" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6530" source="BID">6530</ref>
      <ref url="http://www.securityfocus.com/archive/1/305342" source="BUGTRAQ" adv="1">20030105 S-plus /tmp usage</ref>
      <ref url="http://www.iss.net/security_center/static/11005.php" source="XF">splus-tmp-file-symlink(11005)</ref>
      <ref url="http://www.securitytracker.com/id?1005896" source="SECTRACK">1005896</ref>
      <ref url="http://secunia.com/advisories/7833" source="SECUNIA">7833</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1280" published="2003-12-31" name="CVE-2003-1280" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6550" source="BID">6550</ref>
      <ref url="http://www.securityfocus.com/archive/1/305469" source="BUGTRAQ" adv="1">20030107 Multiple cgihtml vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11022.php" source="XF">cgihtml-dotdot-directory-traversal(11022)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eekim" name="cgihtml">
        <vers num="1.69" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1281" published="2003-12-31" name="CVE-2003-1281" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6552" source="BID">6552</ref>
      <ref url="http://www.securityfocus.com/archive/1/305469" source="BUGTRAQ" adv="1">20030107 Multiple cgihtml vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11023.php" source="XF">cgihtml-tmpfile-symlink(11023)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eekim" name="cgihtml">
        <vers num="1.69" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1282" published="2003-12-31" name="CVE-2003-1282" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/securitynews/5CP061F8VS.html" source="MISC" adv="1">http://www.securiteam.com/securitynews/5CP061F8VS.html</ref>
      <ref url="http://www.iss.net/security_center/static/11016.php" source="XF">ibm-netdata-view-variables(11016)</ref>
      <ref url="http://www.securitytracker.com/id?1005890" source="SECTRACK">1005890</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1283" published="2003-12-31" name="CVE-2003-1283" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6543" source="BID">6543</ref>
      <ref url="http://www.iss.net/security_center/static/11031.php" source="XF">kazaa-ad-local-zone(11031)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0056.html" source="BUGTRAQ">20030107 KaZaA - Bad Zone</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kazaa" name="kazaa_media_desktop">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1284" published="2003-12-31" name="CVE-2003-1284" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13305" source="XF" patch="1">sambar-multiple-vulnerabilities(13305)</ref>
      <ref url="http://securitytracker.com/id?1007819" source="SECTRACK" patch="1">1007819</ref>
      <ref url="http://www.sambar.com/security.htm" source="CONFIRM" adv="1">http://www.sambar.com/security.htm</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/9578" source="SECUNIA" adv="1">9578</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1285" published="2003-12-31" name="CVE-2003-1285" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3) environ.pl, (4) the query parameter to samples/search.dll, (5) the price parameter to mortgage.pl, (6) the query string in dumpenv.pl, (7) the query string to dumpenv.pl, and (8) the E-Mail field of the guestbook script (book.pl).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16056" source="XF" patch="1">sambar-multiple-xss(16056)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13305" source="XF" patch="1">sambar-multiple-vulnerabilities(13305)</ref>
      <ref url="http://www.osvdb.org/5805" source="OSVDB" patch="1">5805</ref>
      <ref url="http://www.osvdb.org/5785" source="OSVDB" patch="1">5785</ref>
      <ref url="http://www.osvdb.org/5784" source="OSVDB" patch="1">5784</ref>
      <ref url="http://www.osvdb.org/5783" source="OSVDB" patch="1">5783</ref>
      <ref url="http://www.osvdb.org/5782" source="OSVDB" patch="1">5782</ref>
      <ref url="http://securitytracker.com/id?1007819" source="SECTRACK" patch="1">1007819</ref>
      <ref url="http://secunia.com/advisories/9578" source="SECUNIA" patch="1">9578</ref>
      <ref url="http://www.sambar.com/security.htm" source="CONFIRM" adv="1">http://www.sambar.com/security.htm</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="beta3" />
        <vers num="5.0" edition="beta4" />
        <vers num="5.0" edition="beta5" />
        <vers num="5.0" edition="beta6" />
        <vers num="5.1" edition="beta1" />
        <vers num="5.1" edition="beta2" />
        <vers num="5.1" edition="beta3" />
        <vers num="5.1" edition="beta4" />
        <vers num="5.1" edition="beta5" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
        <vers num="6.0" edition="beta3" />
        <vers num="6.0" edition="beta4" />
        <vers num="6.0" edition="beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1286" published="2003-12-31" name="CVE-2003-1286" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16054" source="XF" patch="1">sambar-http-gain-access(16054)</ref>
      <ref url="http://www.securityfocus.com/bid/10256" source="BID" patch="1">10256</ref>
      <ref url="http://securitytracker.com/id?1007819" source="SECTRACK" patch="1">1007819</ref>
      <ref url="http://www.sambar.com/security.htm" source="CONFIRM" adv="1">http://www.sambar.com/security.htm</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/9578" source="SECUNIA" adv="1">9578</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html" source="BUGTRAQ" adv="1">20040430 SECURITY.NNOV: Sambar security quest</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="beta3" />
        <vers num="5.0" edition="beta4" />
        <vers num="5.0" edition="beta5" />
        <vers num="5.0" edition="beta6" />
        <vers num="5.1" edition="beta1" />
        <vers num="5.1" edition="beta2" />
        <vers num="5.1" edition="beta3" />
        <vers num="5.1" edition="beta4" />
        <vers num="5.1" edition="beta5" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
        <vers num="6.0" edition="beta3" />
        <vers num="6.0" edition="beta4" />
        <vers num="6.0" edition="beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1287" published="2003-12-31" name="CVE-2003-1287" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16059" source="XF" patch="1">sambar-post-code-execution(16059)</ref>
      <ref url="http://www.osvdb.org/5781" source="OSVDB" patch="1">5781</ref>
      <ref url="http://securitytracker.com/id?1007819" source="SECTRACK" patch="1">1007819</ref>
      <ref url="http://www.sambar.com/security.htm" source="CONFIRM" adv="1">http://www.sambar.com/security.htm</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/9578" source="SECUNIA" adv="1">9578</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html" source="BUGTRAQ" adv="1">20040430 SECURITY.NNOV: Sambar security quest</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="beta3" />
        <vers num="5.0" edition="beta4" />
        <vers num="5.0" edition="beta5" />
        <vers num="5.0" edition="beta6" />
        <vers num="5.1" edition="beta1" />
        <vers num="5.1" edition="beta2" />
        <vers num="5.1" edition="beta3" />
        <vers num="5.1" edition="beta4" />
        <vers num="5.1" edition="beta5" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1288" published="2003-12-31" name="CVE-2003-1288" modified="2008-09-05" discovered="2003-12-18" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and (e) vc_new_s_context functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7587" source="OSVDB" patch="1">7587</ref>
      <ref url="http://list.linux-vserver.org/archive/vserver/msg05658.html" source="MLIST">[Vserver] 20031220 Re: SMP oops 2.4.23 v1.22</ref>
      <ref url="http://list.linux-vserver.org/archive/vserver/msg05631.html" source="MLIST">[Vserver] 20031219 Re: SMP oops 2.4.23 v1.22</ref>
      <ref url="http://list.linux-vserver.org/archive/vserver/msg05630.html" source="MLIST">[Vserver] 20031218 SMP oops 2.4.23 v1.22</ref>
      <ref url="http://linux-vserver.org/ChangeLog" source="CONFIRM">http://linux-vserver.org/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vserver" name="linux-vserver">
        <vers num="1.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1289" published="2003-12-31" name="CVE-2003-1289" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12892" source="XF" patch="1">freebsd-ibcs2-kernel-memory(12892)</ref>
      <ref url="http://www.osvdb.org/2406" source="OSVDB" patch="1">2406</ref>
      <ref url="http://securitytracker.com/id?1007460" source="SECTRACK" patch="1" adv="1">1007460</ref>
      <ref url="http://secunia.com/advisories/9504" source="SECUNIA" patch="1" adv="1">9504</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:10.ibcs2.asc" source="FREEBSD">FreeBSD-SA-03:10</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1290" published="2003-12-31" name="CVE-2003-1290" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9034" source="BID" patch="1">9034</ref>
      <ref url="http://secunia.com/advisories/10218" source="SECUNIA" patch="1" adv="1">10218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13752" source="XF">weblogic-mbeanhome-obtain-information(13752)</ref>
      <ref url="http://www.securityfocus.com/bid/16215" source="BID">16215</ref>
      <ref url="http://www.osvdb.org/3064" source="OSVDB">3064</ref>
      <ref url="http://secunia.com/advisories/18396" source="SECUNIA" adv="1">18396</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/162" source="BEA" adv="1">BEA03-43.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp1:win32" />
        <vers num="6.0" edition="sp1:express" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:express" />
        <vers num="6.0" edition="sp2:win32" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:win32" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp3" />
        <vers num="8.1" edition="sp3:win32" />
        <vers num="8.1" edition="sp3:express" />
        <vers num="8.1" edition="sp4" />
        <vers num="8.1" edition="sp4:express" />
        <vers num="8.1" edition="sp4:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1291" published="2003-12-31" name="CVE-2003-1291" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/download/esx/esx152-patch4.html" source="CONFIRM" patch="1">http://www.vmware.com/download/esx/esx152-patch4.html</ref>
      <ref url="http://www.osvdb.org/21585" source="OSVDB" patch="1">21585</ref>
      <ref url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_sid=dsxk%2ABWh&amp;p_lva=&amp;p_faqid=1108" source="CONFIRM">http://www.vmware.com/support/kb/enduser/std_adp.php?p_sid=dsxk*BWh&amp;p_lva=&amp;p_faqid=1108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="esx_server">
        <vers num="1.5.2" edition="patch1" />
        <vers num="1.5.2" edition="patch2" />
        <vers num="1.5.2" edition="patch3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1292" published="2003-12-31" name="CVE-2003-1292" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/18248" source="BID">18248</ref>
      <ref url="http://www.securityfocus.com/bid/16436" source="BID">16436</ref>
      <ref url="http://www.securityfocus.com/archive/1/329910" source="BUGTRAQ">20030720 sorry, wrong file</ref>
      <ref url="http://www.milw0rm.com/exploits/1864" source="MILW0RM">1864</ref>
      <ref url="http://secunia.com/advisories/9331" source="SECUNIA">9331</ref>
      <ref url="http://forums.ashwebstudio.com/viewtopic.php?t=353&amp;start=0" source="CONFIRM">http://forums.ashwebstudio.com/viewtopic.php?t=353&amp;start=0</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0980.html" source="FULLDISC">20060131 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0979.html" source="FULLDISC">20060131 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0969.html" source="FULLDISC">20060130 Re: ashnews Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashwebstudio" name="ashnews">
        <vers num="0.83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1293" published="2003-12-31" name="CVE-2003-1293" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8025" source="BID">8025</ref>
      <ref url="http://www.securityfocus.com/archive/1/326506" source="BUGTRAQ" adv="1">20030724 GuestBookHost : Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukedweb" name="guestbookhost">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1294" published="2003-12-31" name="CVE-2003-1294" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=124968" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=124968</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1948" source="VUPEN">ADV-2006-1948</ref>
      <ref url="http://www.securityfocus.com/bid/9125" source="BID">9125</ref>
      <ref url="http://www.novell.com/linux/download/updates/90_i386.html" source="CONFIRM">http://www.novell.com/linux/download/updates/90_i386.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10848" source="OVAL">oval:org.mitre.oval:def:10848</ref>
      <ref url="http://jwz.livejournal.com/310943.html" source="MISC">http://jwz.livejournal.com/310943.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0498.html" source="REDHAT">RHSA-2006:0498</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm</ref>
      <ref url="http://secunia.com/advisories/20782" source="SECUNIA">20782</ref>
      <ref url="http://secunia.com/advisories/20456" source="SECUNIA">20456</ref>
      <ref url="http://secunia.com/advisories/20226" source="SECUNIA">20226</ref>
      <ref url="http://secunia.com/advisories/20224" source="SECUNIA">20224</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" source="SGI">20060602-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xscreensaver" name="xscreensaver">
        <vers num="4.05_150" />
        <vers num="4.05_5cl" />
        <vers num="4.05_6" />
        <vers num="4.05_6a" />
        <vers num="4.07_2" />
        <vers num="4.08_29135cl" />
        <vers num="4.09_0" />
        <vers num="4.10_15" />
        <vers num="4.10_4" />
        <vers num="4.10_6" />
        <vers num="4.10_8" />
        <vers num="4.11_0" />
        <vers num="4.12_58" />
        <vers num="4.12_62" />
        <vers num="4.14_0" />
        <vers num="4.14_2" />
        <vers num="4.14_4" />
        <vers num="4.14_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1295" published="2003-12-31" name="CVE-2003-1295" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/download/updates/90_i386.html" source="CONFIRM" patch="1">http://www.novell.com/linux/download/updates/90_i386.html</ref>
      <ref url="http://www.securityfocus.com/bid/9125" source="BID" adv="1">9125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1296" published="2003-12-31" name="CVE-2003-1296" modified="2008-09-05" discovered="2003-09-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Easy File Sharing (EFS) Web Server 1.2 allows remote authenticated users to cause a denial of service via (1) an "empty symbol" in the Title field or (2) certain data in the Your Message field, possibly a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13360" source="XF">easyfilesharing-title-dos(13360)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0083.html" source="BUGTRAQ" adv="1">20031004 Vulnerabilities in Easy File Sharing Web Server (1.2 NEW)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1297" published="2003-12-31" name="CVE-2003-1297" modified="2008-09-05" discovered="2003-09-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obtain sensitive information including an SMTP account username and password hash, the server configuration, and server log files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/23795" source="OSVDB" patch="1">23795</ref>
      <ref url="http://www.osvdb.org/23794" source="OSVDB" patch="1">23794</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0083.html" source="BUGTRAQ">20031004 Vulnerabilities in Easy File Sharing Web Server (1.2 NEW)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1298" published="2003-12-31" name="CVE-2003-1298" modified="2011-03-07" discovered="2003-02-24" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with "./.." (dot slash dot dot).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25396" source="XF">anyportalphp-siteman-directory-traversal(25396)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1053" source="VUPEN">ADV-2006-1053</ref>
      <ref url="http://www.securityfocus.com/bid/17197" source="BID">17197</ref>
      <ref url="http://www.osvdb.org/23984" source="OSVDB">23984</ref>
      <ref url="http://secunia.com/advisories/19359" source="SECUNIA" adv="1">19359</ref>
      <ref url="http://nger.org/anyportal/forum/read.php?f=1&amp;i=152&amp;t=152#reply_152" source="MISC">http://nger.org/anyportal/forum/read.php?f=1&amp;i=152&amp;t=152#reply_152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anyportal_php" name="anyportal_php">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1299" published="2003-12-31" name="CVE-2003-1299" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html" source="CONFIRM" patch="1">http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html</ref>
      <ref url="http://www.osvdb.org/24538" source="OSVDB">24538</ref>
      <ref url="http://packetstormsecurity.org/0305-exploits/baby.txt" source="MISC">http://packetstormsecurity.org/0305-exploits/baby.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablo_software_solutions" name="baby_ftp_server">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1300" published="2003-12-31" name="CVE-2003-1300" modified="2008-09-05" discovered="2003-05-28" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html" source="CONFIRM" patch="1">http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html</ref>
      <ref url="http://www.osvdb.org/24539" source="OSVDB">24539</ref>
      <ref url="http://packetstormsecurity.org/0305-exploits/baby.txt" source="MISC">http://packetstormsecurity.org/0305-exploits/baby.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablo_software_solutions" name="baby_ftp_server">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1301" published="2003-12-31" name="CVE-2003-1301" modified="2008-09-05" discovered="2000-12-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434705/100/0/threaded" source="BUGTRAQ">20060521 Generic Browser Crash with Java 1.4.2_11, Java 1.5.0_06</ref>
      <ref url="http://www.illegalaccess.org/exploit/ObjectStackOverflow.html" source="MISC">http://www.illegalaccess.org/exploit/ObjectStackOverflow.html</ref>
      <ref url="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4944300" source="MISC">http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4944300</ref>
      <ref url="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4396719" source="MISC">http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4396719</ref>
      <ref url="http://www.securityfocus.com/bid/18058" source="BID">18058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update10" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.5.0" edition="update1" />
        <vers num="1.5.0" edition="update2" />
        <vers num="1.5.0" edition="update3" />
        <vers num="1.5.0" edition="update4" />
        <vers num="1.5.0" edition="update5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1302" published="2003-12-31" name="CVE-2003-1302" modified="2008-09-05" discovered="2003-02-04" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040</ref>
      <ref url="http://bugs.php.net/bug.php?id=22048" source="CONFIRM">http://bugs.php.net/bug.php?id=22048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1303" published="2003-12-31" name="CVE-2003-1303" modified="2010-08-21" discovered="2003-06-12" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040" source="CONFIRM" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10346" source="OVAL">oval:org.mitre.oval:def:10346</ref>
      <ref url="http://bugs.php.net/bug.php?id=24150" source="CONFIRM">http://bugs.php.net/bug.php?id=24150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1304" published="2003-12-31" name="CVE-2003-1304" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/9816" source="XF">shopping-cart-database-access(9816)</ref>
      <ref url="http://www.securityfocus.com/bid/8112" source="BID">8112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438189/100/200/threaded" source="BUGTRAQ">20060622 productcart soltan_defacer</ref>
      <ref url="http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf" source="MISC">http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf</ref>
      <ref url="http://secunia.com/advisories/9195" source="SECUNIA">9195</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/0081.html" source="FULLDISC">20030705 [Vulnerability] : ProductCart database file can be downloaded remotely</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5002" />
        <vers num="1.5003" />
        <vers num="1.5003r" />
        <vers num="1.5004" />
        <vers num="1.6002" />
        <vers num="1.6003" />
        <vers num="1.6_b" />
        <vers num="1.6_b001" />
        <vers num="1.6_b002" />
        <vers num="1.6_b003" />
        <vers num="1.6_br" />
        <vers num="1.6_br001" />
        <vers num="1.6_br003" />
        <vers num="1.6b" />
        <vers num="1.6b001" />
        <vers num="1.6b002" />
        <vers num="1.6b003" />
        <vers num="1.6br" />
        <vers num="1.6br001" />
        <vers num="1.6br003" />
        <vers num="2" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1305" published="2003-12-31" name="CVE-2003-1305" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/2291" source="OSVDB">2291</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2003/07/msg00068.html" source="BUGTRAQ">20030707 Internet Explorer Crash</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1306" published="2003-12-31" name="CVE-2003-1306" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the RemoveServerHeader option is enabled.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/29370" source="OSVDB">29370</ref>
      <ref url="http://secunia.com/advisories/9194" source="SECUNIA" adv="1">9194</ref>
      <ref url="http://archives.neohapsis.com/archives/sf/www-mobile/2003-q3/0021.html" source="MLIST">[WWW-Mobile-Code] 20030706 can - IIS Version Disclosure</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1307" published="2003-12-31" name="CVE-2003-1307" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port.  NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9302" source="BID">9302</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449298/100/0/threaded" source="BUGTRAQ" adv="1">20061020 Re: PHP "exec", "system", "popen" (+small POC)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449234/100/0/threaded" source="BUGTRAQ" adv="1">20061019 PHP "exec", "system", "popen" problem</ref>
      <ref url="http://www.securityfocus.com/archive/1/348368" source="BUGTRAQ" adv="1">20031226 Hijacking Apache https by mod_php</ref>
      <ref url="http://hackerdom.ru/~dimmo/phpexpl.c" source="MISC">http://hackerdom.ru/~dimmo/phpexpl.c</ref>
      <ref url="http://bugs.php.net/38915" source="MISC">http://bugs.php.net/38915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" edition="beta" />
        <vers num="2.0.28" edition="beta:win32" />
        <vers num="2.0.32" edition="beta" />
        <vers num="2.0.32" edition="beta:win32" />
        <vers num="2.0.34" edition="beta" />
        <vers num="2.0.34" edition="beta:win32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" edition="" />
        <vers num="2.0.46" edition=":win32" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1308" published="2003-12-31" name="CVE-2003-1308" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9161" source="BID" patch="1">9161</ref>
      <ref url="http://www.fvwm.org/news/" source="CONFIRM">http://www.fvwm.org/news/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fvwm" name="fvwm">
        <vers prev="1" num="2.4.17" />
        <vers prev="1" num="2.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1309" published="2003-12-31" name="CVE-2003-1309" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12824" source="XF" patch="1" adv="1">device-driver-gain-privileges(12824)</ref>
      <ref url="http://www.osvdb.org/4362" source="OSVDB" patch="1" adv="1">4362</ref>
      <ref url="http://www.osvdb.org/2375" source="OSVDB" patch="1" adv="1">2375</ref>
      <ref url="http://secunia.com/advisories/9459" source="SECUNIA" patch="1" adv="1">9459</ref>
      <ref url="http://www.securityfocus.com/bid/8342" source="BID" adv="1">8342</ref>
      <ref url="http://download.zonelabs.com/bin/free/information/znalm/zaReleaseHistory.html" source="CONFIRM">http://download.zonelabs.com/bin/free/information/znalm/zaReleaseHistory.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0070.html" source="VULNWATCH" adv="1">20030805 Local ZoneAlarm Firewall (probably all versions - tested on v3.1)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="3.7.202" />
        <vers num="3.7.211" edition="" />
        <vers num="3.7.211" edition=":plus" />
        <vers num="3.7.211" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1310" published="2003-12-31" name="CVE-2003-1310" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12824" source="XF">device-driver-gain-privileges(12824)</ref>
      <ref url="http://www.securityfocus.com/bid/8329" source="BID">8329</ref>
      <ref url="http://www.osvdb.org/4362" source="OSVDB">4362</ref>
      <ref url="http://secunia.com/advisories/9460" source="SECUNIA" adv="1">9460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1311" published="2003-12-31" name="CVE-2003-1311" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/30741" source="OSVDB">30741</ref>
      <ref url="http://curl.haxx.se/mail/archive-2003-05/0172.html" source="MLIST">[curl-users] 20030529 Re: https, redirection and authentication using POST</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1312" published="2003-12-31" name="CVE-2003-1312" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/30741" source="OSVDB">30741</ref>
      <ref url="http://curl.haxx.se/mail/archive-2003-05/0172.html" source="MLIST">[curl-users] 20030529 Re: https, redirection and authentication using POST</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1313" published="2003-12-31" name="CVE-2003-1313" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8767" source="BID">8767</ref>
      <ref url="http://www.securityfocus.com/archive/1/340244" source="VULNWATCH">20031004 EMML, EMGB : Include() hole</ref>
      <ref url="http://securitytracker.com/id?1007884" source="SECTRACK">1007884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eternalmart" name="mailing_list_manager">
        <vers num="1.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1314" published="2003-12-31" name="CVE-2003-1314" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8767" source="BID">8767</ref>
      <ref url="http://www.securityfocus.com/bid/21720" source="BID">21720</ref>
      <ref url="http://www.securityfocus.com/archive/1/340244" source="VULNWATCH">20031004 EMML, EMGB : Include() hole</ref>
      <ref url="http://securitytracker.com/id?1007885" source="SECTRACK">1007885</ref>
      <ref url="http://milw0rm.com/exploits/2980" source="MILW0RM">2980</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eternalmart" name="eternalmart_guestbook">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1315" published="2003-12-31" name="CVE-2003-1315" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13922" source="XF">landdownunder-auth-sql-injection(13922)</ref>
      <ref url="http://www.securityfocus.com/bid/9168" source="BID">9168</ref>
      <ref url="http://www.osvdb.org/2943" source="OSVDB">2943</ref>
      <ref url="http://www.neocrome.net/page.php?id=1250" source="MISC">http://www.neocrome.net/page.php?id=1250</ref>
      <ref url="http://www.neocrome.net/index.php?m=single&amp;id=76" source="MISC">http://www.neocrome.net/index.php?m=single&amp;id=76</ref>
      <ref url="http://securitytracker.com/id?1008416" source="SECTRACK">1008416</ref>
      <ref url="http://secunia.com/advisories/10396" source="SECUNIA" adv="1">10396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neocrome" name="land_down_under">
        <vers num="701" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1316" published="2003-12-31" name="CVE-2003-1316" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod.php in eNdonesia 8.2 allows remote attackers to obtain sensitive information via a ' (quote) value in the lng parameter, which reveals the path in an error message.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13042" source="XF" adv="1">endonesia-mod-path-disclosure(13042)</ref>
      <ref url="http://www.securityfocus.com/bid/8507" source="BID" adv="1">8507</ref>
      <ref url="http://www.osvdb.org/3666" source="OSVDB" adv="1">3666</ref>
      <ref url="http://securitytracker.com/id?1007592" source="SECTRACK" adv="1">1007592</ref>
      <ref url="http://secunia.com/advisories/9622" source="SECUNIA" adv="1">9622</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1317" published="2003-12-31" name="CVE-2003-1317" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13041" source="XF" adv="1">endonesia-mod-xss(13041)</ref>
      <ref url="http://www.securityfocus.com/bid/8506" source="BID" adv="1">8506</ref>
      <ref url="http://www.osvdb.org/2480" source="OSVDB" adv="1">2480</ref>
      <ref url="http://securitytracker.com/id?1007592" source="SECTRACK" adv="1">1007592</ref>
      <ref url="http://secunia.com/advisories/9622" source="SECUNIA" adv="1">9622</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1318" published="2003-12-31" name="CVE-2003-1318" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tripbit.org/advisories/twilight_advisory.txt" source="MISC">http://www.tripbit.org/advisories/twilight_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/bid/22090" source="BID">22090</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820430209748&amp;w=2" source="BUGTRAQ">20030713 TA-2003-07 Denial of Service Attack against Twilight WebServer v1.3.3.0</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1319" published="2003-12-31" name="CVE-2003-1319" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12231" source="XF" patch="1">smartftp-long-list-bo(12231)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12228" source="XF" patch="1">smartftp-pwd-directory-bo(12228)</ref>
      <ref url="http://www.securityfocus.com/bid/7861" source="BID" patch="1">7861</ref>
      <ref url="http://www.securityfocus.com/bid/7858" source="BID" patch="1">7858</ref>
      <ref url="http://secunia.com/advisories/8998" source="SECUNIA" patch="1" adv="1">8998</ref>
      <ref url="http://securitytracker.com/id?1006956" source="SECTRACK" adv="1">1006956</ref>
      <ref url="http://security.nnov.ru/docs4679.html" source="MISC" adv="1">http://security.nnov.ru/docs4679.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0083.html" source="BUGTRAQ" adv="1">20030608 [SmartFTP] Two Buffer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartftp" name="smartftp">
        <vers prev="1" num="1.0.973" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1320" published="2003-12-31" name="CVE-2003-1320" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/287771" source="CERT-VN">VU#287771</ref>
      <ref url="http://www.kb.cert.org/vuls/id/AAMN-5L74VD" source="MISC">http://www.kb.cert.org/vuls/id/AAMN-5L74VD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicwall" name="firmware">
        <vers prev="1" num="6.4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1321" published="2003-12-31" name="CVE-2003-1321" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12974" source="XF" adv="1">avantbrowser-http-bo(12974)</ref>
      <ref url="http://www.securityfocus.com/bid/8471" source="BID">8471</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=106150462504484&amp;w=2" source="BUGTRAQ">20030821 Buffer overflow in Avant Browser 8.02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avant_force" name="avant_browser">
        <vers num="8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1322" published="2003-12-31" name="CVE-2003-1322" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/324136" source="BUGTRAQ" patch="1" adv="1">20030606 Multiple Buffer Overflow Vulnerabilities Found in MERCUR Mail server v.4.2 (SP2) - IMAP protocol</ref>
      <ref url="http://www.securityfocus.com/bid/7842" source="BID">7842</ref>
      <ref url="http://www.iss.net/security_center/static/12203.php" source="XF">mercur-multiple-bo(12203)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_mailserver">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1323" published="2003-12-31" name="CVE-2003-1323" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz" source="CONFIRM" patch="1">http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elm_development_group" name="elm">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1324" published="2003-12-31" name="CVE-2003-1324" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz" source="CONFIRM" patch="1">http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elmme-mailer" name="elm_me+">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1325" published="2003-12-31" name="CVE-2003-1325" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_base_score="5.2">
    <desc>
      <descript source="cve">The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://packetstormsecurity.org/0304-exploits/hl-headnut.c" source="MISC">http://packetstormsecurity.org/0304-exploits/hl-headnut.c</ref>
      <ref url="http://aluigi.altervista.org/adv/csdos.txt" source="MISC">http://aluigi.altervista.org/adv/csdos.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valve_software" name="half-life_cstrike_dedicated_server">
        <vers prev="1" num="1.1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1326" published="2003-02-19" name="CVE-2003-1326" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-004.asp" source="MS" patch="1" adv="1">MS03-004</ref>
      <ref url="http://www.iss.net/security_center/static/11258.php" source="XF" adv="1">ie-dialog-zone-bypass(11258)</ref>
      <ref url="http://www.securityfocus.com/bid/6779" source="BID">6779</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-038.shtml" source="CIAC">N-038</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:49" source="OVAL" sig="1">oval:org.mitre.oval:def:49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:178" source="OVAL" sig="1">oval:org.mitre.oval:def:178</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:126" source="OVAL" sig="1">oval:org.mitre.oval:def:126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1327" published="2003-12-31" name="CVE-2003-1327" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the option "MAIL_ADMIN" has been enabled (not default), that anonymous users have write permissions on a folder, and that the program has been compiled on a system where very long paths are permitted.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13269" source="XF">wuftp-mailadmin-sockprintf-bo(13269)</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2003&amp;m=slackware-security.365971" source="SLACKWARE">SSA:2003-259-03</ref>
      <ref url="http://www.securityfocus.com/bid/8668" source="BID">8668</ref>
      <ref url="http://www.osvdb.org/2594" source="OSVDB">2594</ref>
      <ref url="http://securitytracker.com/id?1007775" source="SECTRACK">1007775</ref>
      <ref url="http://secunia.com/advisories/9835" source="SECUNIA" adv="1">9835</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0348.html" source="BUGTRAQ">20030922 Wu_ftpd all versions (not) vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers prev="1" num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1328" published="2003-02-19" name="CVE-2003-1328" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/400577" source="CERT-VN">VU#400577</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-004.asp" source="MS" patch="1" adv="1">MS03-004</ref>
      <ref url="http://www.iss.net/security_center/static/11259.php" source="XF" adv="1">ie-showhelp-zone-bypass(11259)</ref>
      <ref url="http://www.securityfocus.com/bid/6780" source="BID">6780</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-038.shtml" source="CIAC">N-038</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0083.html" source="BUGTRAQ">20030206 showHelp("file:") disables security in IE - Sandblad advisory #11</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:57" source="OVAL" sig="1">oval:org.mitre.oval:def:57</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1329" published="2003-12-31" name="CVE-2003-1329" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/connect-dos.patch" source="CONFIRM" patch="1">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/connect-dos.patch</ref>
      <ref url="http://www.osvdb.org/34670" source="OSVDB">34670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1330" published="2003-12-31" name="CVE-2003-1330" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11745" source="XF">mailsweeper-onstrip-bypass-filter(11745)</ref>
      <ref url="http://www.securityfocus.com/bid/7226" source="BID">7226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift_limited" name="mailsweeper">
        <vers num="4.3.6_sp1" edition="" />
        <vers num="4.3.6_sp1" edition=":smtp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1331" published="2003-12-31" name="CVE-2003-1331" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12337" source="XF">mysql-mysqlrealconnect-bo(12337)</ref>
      <ref url="http://www.securityfocus.com/bid/7887" source="BID">7887</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=564" source="CONFIRM">http://bugs.mysql.com/bug.php?id=564</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html" source="FULLDISC">20030612 libmysqlclient 4.x and below mysql_real_connect() buffer overflow.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="4.0.9" edition="gamma" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1332" published="2003-12-31" name="CVE-2003-1332" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12749" source="XF" patch="1">samba-reply-nttrans-bo(12749)</ref>
      <ref url="http://www.securiteam.com/exploits/5TP0M2AAKS.html" source="MISC">http://www.securiteam.com/exploits/5TP0M2AAKS.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-096.html" source="REDHAT">RHSA-2003:096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers prev="1" num="2.2.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1333" published="2003-12-31" name="CVE-2003-1333" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://groups.google.com/group/intersystems-public-cache/browse_thread/thread/8bdc0e496226edd1/60e9179edb4a4d43" source="CONFIRM">http://groups.google.com/group/intersystems-public-cache/browse_thread/thread/8bdc0e496226edd1/60e9179edb4a4d43</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="5" />
        <vers num="5.0.12" />
        <vers num="5.0.17" />
        <vers num="5.0.19" />
        <vers num="5.0.21" />
        <vers num="5.0.3" />
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1334" published="2003-12-31" name="CVE-2003-1334" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.bitfolge.de/snif-en.html" source="CONFIRM">http://www.bitfolge.de/snif-en.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kai_blankenhorn_bitfolge" name="simple_and_nice_index_file">
        <vers prev="1" num="1.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1335" published="2003-12-31" name="CVE-2003-1335" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.bitfolge.de/snif-en.html" source="CONFIRM">http://www.bitfolge.de/snif-en.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kai_blankenhorn_bitfolge" name="simple_and_nice_index_file">
        <vers prev="1" num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1336" published="2003-12-31" name="CVE-2003-1336" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8819" source="BID" patch="1">8819</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6M00B0U8KE.html" source="MISC" patch="1">http://www.securiteam.com/windowsntfocus/6M00B0U8KE.html</ref>
      <ref url="http://secunia.com/advisories/9996" source="SECUNIA" patch="1" adv="1">9996</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0060.html" source="NTBUGTRAQ" patch="1">20031015 mIRC Buffer Overflow in irc protocol handler</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13405" source="XF">mirc-ircprotocol-execute-code(13405)</ref>
      <ref url="http://www.osvdb.org/2665" source="OSVDB">2665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirc" name="mirc">
        <vers prev="1" num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1337" published="2003-12-31" name="CVE-2003-1337" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12466" source="XF" patch="1">abyss-http-get-bo(12466)</ref>
      <ref url="http://www.securityfocus.com/bid/8062" source="BID" patch="1">8062</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0235.html" source="BUGTRAQ">20030629 Aprelium Abyss webserver X1 arbitrary code execution and header injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aprelium_technologies" name="abyss_web_server">
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1338" published="2003-12-31" name="CVE-2003-1338" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/93.html

'http://cwe.mitre.org/data/definitions/93.html'</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0235.html" source="BUGTRAQ">20030629 Aprelium Abyss webserver X1 arbitrary code execution and header injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aprelium_technologies" name="abyss_web_server">
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1339" published="2003-12-31" name="CVE-2003-1339" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/133" source="MILW0RM">133</ref>
      <ref url="http://www.governmentsecurity.org/archive/t5390.html" source="MISC">http://www.governmentsecurity.org/archive/t5390.html</ref>
      <ref url="http://securitytracker.com/id?1008412" source="SECTRACK">1008412</ref>
      <ref url="http://seclists.org/bugtraq/2003/Dec/0195.html" source="BUGTRAQ">20031211 eZ and eZphotoshare fixes</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=107090390002654&amp;w=2" source="BUGTRAQ">20031207 eZ Multiple Packages Stack Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezmeeting" name="ezmeeting">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1340" published="2003-12-31" name="CVE-2003-1340" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/480866/100/0/threaded" source="BUGTRAQ">20070927 Re: [waraxe-2007-SA#056] - Another Sql Injection in NukeSentinel 2.5.11</ref>
      <ref url="http://www.securityfocus.com/archive/1/323425" source="BUGTRAQ">20030530 Php-Nuke:users and admins password hashes vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3185" source="SREASON">3185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnuke" name="php-nuke">
        <vers num="5.6" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1341" published="2003-12-31" name="CVE-2003-1341" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6616" source="BID" patch="1">6616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11059" source="XF">officescan-cgichkmasterpwd-auth-bypass(11059)</ref>
      <ref url="http://www.osvdb.org/6181" source="OSVDB">6181</ref>
      <ref url="http://secunia.com/advisories/7881" source="SECUNIA" adv="1">7881</ref>
      <ref url="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353" source="CONFIRM">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html" source="VULNWATCH">20030114 Assorted Trend Vulns Rev 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":corporate" />
        <vers num="3.0" edition=":corporate_for_windows_nt_server" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":corporate_for_windows_nt_server" />
        <vers num="3.11" edition="" />
        <vers num="3.11" edition=":corporate" />
        <vers num="3.11" edition=":corporate_for_windows_nt_server" />
        <vers num="3.13" edition="" />
        <vers num="3.13" edition=":corporate_for_windows_nt_server" />
        <vers num="3.13" edition=":corporate" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":corporate_for_windows_nt_server" />
        <vers num="3.5" edition=":corporate" />
        <vers num="3.54" edition="" />
        <vers num="3.54" edition=":corporate" />
      </prod>
      <prod vendor="trend_micro" name="virus_buster">
        <vers num="3.52" edition="" />
        <vers num="3.52" edition=":corporate" />
        <vers num="3.53" edition="" />
        <vers num="3.53" edition=":corporate" />
        <vers num="3.54" edition="" />
        <vers num="3.54" edition=":corporate" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1342" published="2003-12-31" name="CVE-2003-1342" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11060" source="XF">trend-vcs-activesupport-dos(11060)</ref>
      <ref url="http://www.securityfocus.com/bid/6617" source="BID">6617</ref>
      <ref url="http://www.osvdb.org/6185" source="OSVDB">6185</ref>
      <ref url="http://secunia.com/advisories/7881" source="SECUNIA" adv="1">7881</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html" source="VULNWATCH">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html" source="VULNWATCH">20030114 Assorted Trend Vulns Rev 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="virus_control_system">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1343" published="2003-12-31" name="CVE-2003-1343" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6619" source="BID" patch="1">6619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11061" source="XF">scanmail-smgsmxcfg30-password-bypass(11061)</ref>
      <ref url="http://secunia.com/advisories/7881" source="SECUNIA" adv="1">7881</ref>
      <ref url="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352" source="CONFIRM">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html" source="VULNWATCH">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="scanmail">
        <vers prev="1" num="3.8" edition="" />
        <vers prev="1" num="3.8" edition=":microsoft_exchange" />
        <vers prev="1" num="6.0" edition="" />
        <vers prev="1" num="6.0" edition=":microsoft_exchange" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1344" published="2003-12-31" name="CVE-2003-1344" modified="2010-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11063" source="XF">trend-vcs-weak-encryption(11063)</ref>
      <ref url="http://www.securityfocus.com/bid/6618" source="BID">6618</ref>
      <ref url="http://secunia.com/advisories/7881" source="SECUNIA" adv="1">7881</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html" source="VULNWATCH">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="virus_control_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1345" published="2003-12-31" name="CVE-2003-1345" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11064" source="XF">webcollection-plus-directory-traversal(11064)</ref>
      <ref url="http://www.securityfocus.com/bid/6574" source="BID">6574</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104261317218210&amp;w=2" source="BUGTRAQ">20030114 Vulnerability in WebCollection Plus (TM)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="follett_software" name="webcollection_plus">
        <vers num="5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1346" published="2003-12-31" name="CVE-2003-1346" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware using AirPlus Access Point Manager.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11074" source="XF">dlink-airplus-restore-default(11074)</ref>
      <ref url="http://www.securitytracker.com/id?1005926" source="SECTRACK">1005926</ref>
      <ref url="http://www.securityfocus.com/bid/6609" source="BID">6609</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104311601319909&amp;w=2" source="BUGTRAQ">20030116 Re: D-Link DWL-900AP+ Security Hole</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104267037431451&amp;w=2" source="BUGTRAQ">20030114 D-Link DWL-900AP+ Security Hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dwl-900ap+">
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1347" published="2003-12-31" name="CVE-2003-1347" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.geeklog.net/filemgmt/visit.php?lid=101" source="CONFIRM" patch="1">http://www.geeklog.net/filemgmt/visit.php?lid=101</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11075" source="XF">geeklog-php-scripts-xss(11075)</ref>
      <ref url="http://www.securityfocus.com/bid/6604" source="BID">6604</ref>
      <ref url="http://www.securityfocus.com/bid/6603" source="BID">6603</ref>
      <ref url="http://www.securityfocus.com/bid/6602" source="BID">6602</ref>
      <ref url="http://www.securityfocus.com/bid/6601" source="BID">6601</ref>
      <ref url="http://www.securityfocus.com/archive/1/306770" source="BUGTRAQ">20030114 Multiple XSS in Geeklog 1.3.7</ref>
      <ref url="http://securityreason.com/securityalert/3226" source="SREASON">3226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geeklog" name="geeklog">
        <vers num="1.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1348" published="2003-12-31" name="CVE-2003-1348" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11155" source="XF">guestbook-multiple-field-xss(11155)</ref>
      <ref url="http://www.securityfocus.com/bid/6686" source="BID">6686</ref>
      <ref url="http://www.securityfocus.com/archive/1/308312" source="BUGTRAQ">20030125 ftls.org  Guestbook 1.1 Script Injection</ref>
      <ref url="http://securityreason.com/securityalert/3227" source="SREASON">3227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftls" name="guestbook">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1349" published="2003-12-31" name="CVE-2003-1349" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11062" source="XF">niteserver-dotdot-directory-traversal(11062)</ref>
      <ref url="http://www.securitytracker.com/id?1005923" source="SECTRACK">1005923</ref>
      <ref url="http://www.securityfocus.com/bid/6648" source="BID">6648</ref>
      <ref url="http://secunia.com/advisories/7879" source="SECUNIA" adv="1">7879</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0022.html" source="VULNWATCH">20030115 Directory traversal vulnerabilities found in NITE ftp-server version 1.83</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomas_krebs" name="niteserver_ftpd">
        <vers num="1.83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1350" published="2003-12-31" name="CVE-2003-1350" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11156" source="XF">listsitepro-account-hijacking(11156)</ref>
      <ref url="http://www.securityfocus.com/bid/6685" source="BID">6685</ref>
      <ref url="http://www.securityfocus.com/archive/1/308300" source="BUGTRAQ">20030124 List Site Pro v2 user account Hijacking vulnerablity</ref>
      <ref url="http://securityreason.com/securityalert/3230" source="SREASON">3230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="list_site_pro" name="list_site_pro">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1351" published="2003-12-31" name="CVE-2003-1351" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11159" source="XF">edittag-dotdot-directory-traversal(11159)</ref>
      <ref url="http://www.securityfocus.com/bid/6675" source="BID">6675</ref>
      <ref url="http://www.securityfocus.com/archive/1/308162" source="BUGTRAQ">20030124 Vulnerability in edittag.pl</ref>
      <ref url="http://securityreason.com/securityalert/3231" source="SREASON">3231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_billock" name="edittag">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1352" published="2003-12-31" name="CVE-2003-1352" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11115" source="XF">gabber-information-leak(11115)</ref>
      <ref url="http://www.securityfocus.com/bid/6624" source="BID">6624</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0179.html" source="BUGTRAQ">20030115 Gabber 0.8.7 leaks presence information without user authorization</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gabber" name="gabber">
        <vers num="0.8.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1353" published="2003-12-31" name="CVE-2003-1353" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11096" source="XF">opt-news-post-xss(11096)</ref>
      <ref url="http://www.securityfocus.com/bid/6631" source="BID">6631</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0119.html" source="BUGTRAQ">20030116 Outreach Project Tool</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lanifex" name="outreach_project_tool">
        <vers num="0.946b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1354" published="2003-12-31" name="CVE-2003-1354" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11084" source="XF">battlefield-udp-query-dos(11084)</ref>
      <ref url="http://www.securityfocus.com/bid/6636" source="BID">6636</ref>
      <ref url="http://www.securiteam.com/securitynews/5EP0O0K8UO.html" source="MISC">http://www.securiteam.com/securitynews/5EP0O0K8UO.html</ref>
      <ref url="http://www.pivx.com/kristovich/adv/mk001/" source="MISC">http://www.pivx.com/kristovich/adv/mk001/</ref>
      <ref url="http://seclists.org/lists/bugtraq/2003/Jan/0178.html" source="BUGTRAQ">20030122 PivX Multi-Vendor Game Server dDoS Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamespy3d" name="gamespy_3d">
        <vers num="2.62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1355" published="2003-12-31" name="CVE-2003-1355" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11426" source="XF">battlefield-remoteconsole-username-dos(11426)</ref>
      <ref url="http://www.securityfocus.com/bid/6967" source="BID">6967</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0342.html" source="BUGTRAQ">20030226 [VSA0307] Battlefield 1942 remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electronic_arts" name="battlefield_1942">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1356" published="2003-12-31" name="CVE-2003-1356" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11107" source="XF" patch="1">hpux-sort-file-handling(11107)</ref>
      <ref url="http://www.securityfocus.com/bid/6640" source="BID" patch="1">6640</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5758" source="OVAL">oval:org.mitre.oval:def:5758</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q1/0009.html" source="HP">SSRT3454</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q1/0009.html" source="HP">SSRT3454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1357" published="2003-12-31" name="CVE-2003-1357" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11185" source="XF">proxyview-administrator-default-password(11185)</ref>
      <ref url="http://www.securityfocus.com/bid/6708" source="BID">6708</ref>
      <ref url="http://www.securityfocus.com/archive/1/308733" source="BUGTRAQ">20030128 ProxyView default undocumented password</ref>
      <ref url="http://securityreason.com/securityalert/3228" source="SREASON">3228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="replicom" name="proxyview">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1358" published="2003-12-31" name="CVE-2003-1358" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11312" source="XF">hp-rsf3000-daemon-access(11312)</ref>
      <ref url="http://www.securityfocus.com/bid/6837" source="BID">6837</ref>
      <ref url="http://www.securityfocus.com/archive/1/324381" source="BUGTRAQ">20030710 [LSD] HP-UX security vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/advisories/4960" source="HP">HPSBUX0302-240</ref>
      <ref url="http://securityreason.com/securityalert/3236" source="SREASON">3236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.26" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="11.0.4" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1359" published="2003-12-31" name="CVE-2003-1359" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11313" source="XF" patch="1">hp-stmkfont-bo(11313)</ref>
      <ref url="http://www.securityfocus.com/bid/6836" source="BID" patch="1">6836</ref>
      <ref url="http://www.securityfocus.com/archive/1/324381" source="BUGTRAQ">20030610 [LSD] HP-UX security vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/advisories/4959" source="HP">HPSBUX0302-241</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5587" source="OVAL">oval:org.mitre.oval:def:5587</ref>
      <ref url="http://securityreason.com/securityalert/3236" source="SREASON">3236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="predictive_dialer_system">
        <vers num="11" />
        <vers num="12" />
        <vers num="9.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.26" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="11.0.4" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1360" published="2003-12-31" name="CVE-2003-1360" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11314" source="XF">hp-landiag-lanadmin-bo(11314)</ref>
      <ref url="http://www.securityfocus.com/bid/6834" source="BID">6834</ref>
      <ref url="http://www.securityfocus.com/archive/1/324381" source="BUGTRAQ">20030610 [LSD] HP-UX security vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/advisories/4957" source="HP">HPSBUX0302-243</ref>
      <ref url="http://securityreason.com/securityalert/3236" source="SREASON">3236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.26" />
        <vers num="10.30" />
        <vers num="10.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1361" published="2003-12-31" name="CVE-2003-1361" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6928" source="BID" patch="1">6928</ref>
      <ref url="http://seer.support.veritas.com/docs/252933.htm" source="CONFIRM" patch="1">http://seer.support.veritas.com/docs/252933.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11418" source="XF">veritas-bmr-root-access(11418)</ref>
      <ref url="http://seer.support.veritas.com/docs/254442.htm" source="CONFIRM">http://seer.support.veritas.com/docs/254442.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html" source="BUGTRAQ">20030225 VERITAS Software Technical Advisory (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="veritas" name="bare_metal_restore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1362" published="2003-12-31" name="CVE-2003-1362" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6878" source="BID" patch="1">6878</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11366" source="XF">hp-bastille-info-disclosure(11366)</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q1/0033.html" source="HP">HPSBUX0302-245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="bastille">
        <vers num="b.02.00.05" edition="" />
        <vers num="b.02.00.05" edition=":hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1363" published="2003-12-31" name="CVE-2003-1363" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6842" source="BID">6842</ref>
      <ref url="http://www.iss.net/security_center/static/11310.php" source="XF">abyss-web-admin-bruteforce(11310)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html" source="BUGTRAQ">20030212 Abyss WebServer Brute Force Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aprelium_technologies" name="abyss_web_server">
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1364" published="2003-12-31" name="CVE-2003-1364" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:C)" CVSS_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7287" source="BID" patch="1">7287</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11718" source="XF">abyss-http-get-dos(11718)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0095.html" source="BUGTRAQ">20030405 Abyss X1 1.1.2 remote crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aprelium_technologies" name="abyss_web_server">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1365" published="2003-12-31" name="CVE-2003-1365" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11308" source="XF">cgilite-shell-command-execution(11308)</ref>
      <ref url="http://www.securityfocus.com/bid/6833" source="BID">6833</ref>
      <ref url="http://www.securityfocus.com/archive/1/311414" source="BUGTRAQ">20030211 Security bug in CGI::Lite::escape_dangerous_chars() function</ref>
      <ref url="http://use.perl.org/~cbrooks/journal/10542" source="MISC">http://use.perl.org/~cbrooks/journal/10542</ref>
      <ref url="http://search.cpan.org/~smylers/CGI-Lite-2.02/Lite.pm" source="CONFIRM">http://search.cpan.org/~smylers/CGI-Lite-2.02/Lite.pm</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0065.html" source="VULNWATCH">20030211 Security bug in CGI::Lite::escape_dangerous_chars() function</ref>
      <ref url="http://securityreason.com/securityalert/3237" source="SREASON">3237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perl" name="cgi_lite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1366" published="2003-12-31" name="CVE-2003-1366" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11233" source="XF" patch="1">openbsd-chpass-information-disclosure(11233)</ref>
      <ref url="http://www.securityfocus.com/bid/6748" source="BID">6748</ref>
      <ref url="http://www.securityfocus.com/archive/1/309962" source="BUGTRAQ">20030203 ASA-0001: OpenBSD chpass/chfn/chsh file content leak</ref>
      <ref url="http://www.securitytracker.com/id?1006035" source="SECTRACK">1006035</ref>
      <ref url="http://securityreason.com/securityalert/3238" source="SREASON">3238</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1367" published="2003-12-31" name="CVE-2003-1367" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11243" source="XF">majordomo-whichaccess-email-disclosure(11243)</ref>
      <ref url="http://www.securityfocus.com/bid/6761" source="BID">6761</ref>
      <ref url="http://www.securityfocus.com/archive/1/310113" source="BUGTRAQ">20030204 Majordomo info leakage, all versions</ref>
      <ref url="http://securityreason.com/securityalert/3235" source="SREASON">3235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="great_circle_associates" name="majordomo">
        <vers num="1.94.4" />
        <vers num="1.94.5" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1368" published="2003-12-31" name="CVE-2003-1368" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11234" source="XF">32bit-ftp-banner-bo(11234)</ref>
      <ref url="http://www.securityfocus.com/bid/6764" source="BID">6764</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0054.html" source="VULNWATCH">20030204 Banner Buffer Overflows found in Multible FTP Clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrasoft" name="ftp_client">
        <vers num="9.49.01" edition="" />
        <vers num="9.49.01" edition=":32bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1369" published="2003-12-31" name="CVE-2003-1369" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11235" source="XF">bytecatcher-ftp-banner-bo(11235)</ref>
      <ref url="http://www.securityfocus.com/bid/6762" source="BID">6762</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0054.html" source="VULNWATCH">20030204 Banner Buffer Overflows found in Multible FTP Clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="save_it_software_pty" name="bytecatcherftp">
        <vers num="1.04b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1370" published="2003-12-31" name="CVE-2003-1370" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6700" source="BID" patch="1">6700</ref>
      <ref url="http://www.securityfocus.com/bid/6697" source="BID" patch="1">6697</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11176" source="XF">nuked-klan-index-xss(11176)</ref>
      <ref url="http://www.securityfocus.com/bid/6699" source="BID">6699</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0330.html" source="BUGTRAQ">20030127 [SCSA-003] Multiple Cross Site Scripting &amp; Script Injection Vulnerabilities in Nuked-Klan</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1371" published="2003-12-31" name="CVE-2003-1371" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11424" source="XF">nukedklan-information-disclosure(11424)</ref>
      <ref url="http://www.securityfocus.com/bid/6917" source="BID">6917</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html" source="BUGTRAQ">20030221 [SCSA-006] XSS &amp; Function Execution Vulnerabilities in Nuked-Klan</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1372" published="2003-12-31" name="CVE-2003-1372" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11376" source="XF">phpbb-index-sql-injection(11376)</ref>
      <ref url="http://www.securityfocus.com/bid/6892" source="BID">6892</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0231.html" source="BUGTRAQ">20030219 myphpnuke xss</ref>
      <ref url="http://www.osvdb.org/3931" source="OSVDB">3931</ref>
      <ref url="http://secunia.com/advisories/8125" source="SECUNIA">8125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpnuke" name="myphpnuke">
        <vers num="1.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1373" published="2003-12-31" name="CVE-2003-1373" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11407" source="XF" patch="1">phpbb-auth-read-files(11407)</ref>
      <ref url="http://www.securityfocus.com/bid/6889" source="BID">6889</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0245.html" source="BUGTRAQ">20030220 phpBB Security Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1374" published="2003-12-31" name="CVE-2003-1374" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in disable of HP-UX 11.0 may allow local users to execute arbitrary code via a long argument to the (1) -r or (2)-c options.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11316" source="XF">hp-lp-disable-bo(11316)</ref>
      <ref url="http://www.securityfocus.com/bid/6845" source="BID">6845</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0156.html" source="BUGTRAQ">20030213 HPUX disable buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1375" published="2003-12-31" name="CVE-2003-1375" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6800" source="BID" patch="1">6800</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11272" source="XF">hp-wall-bo(11272)</ref>
      <ref url="http://www.securityfocus.com/archive/1/310908" source="BUGTRAQ">20030207 HPUX Wall Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/advisories/5369" source="HP">HPSBUX0305-258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5439" source="OVAL">oval:org.mitre.oval:def:5439</ref>
      <ref url="http://securityreason.com/securityalert/3264" source="SREASON">3264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1376" published="2003-12-31" name="CVE-2003-1376" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11296" source="XF">winzip-pkzip-weak-encryption(11296)</ref>
      <ref url="http://www.securityfocus.com/bid/6805" source="BID">6805</ref>
      <ref url="http://www.securityfocus.com/archive/1/311059" source="BUGTRAQ">20030208 Yet another plaintext attack to ZIP encryption scheme.</ref>
      <ref url="http://securityreason.com/securityalert/3265" source="SREASON">3265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winzip" name="winzip">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1377" published="2003-12-31" name="CVE-2003-1377" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:C)" CVSS_score="8.3" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="8.6" CVSS_base_score="8.3">
    <desc>
      <descript source="cve">Buffer overflow in the reverse DNS lookup of Smart IRC Daemon (SIRCD) 0.4.0 and 0.4.4 allows remote attackers to execute arbitrary code via a client with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11409" source="XF">sircd-reverse-dns-bo(11409)</ref>
      <ref url="http://www.securityfocus.com/bid/6924" source="BID">6924</ref>
      <ref url="http://www.securityfocus.com/archive/1/312924" source="BUGTRAQ">20030223 sircd proof-of-concept / advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sircd" name="sircd">
        <vers num="0.4.0" />
        <vers num="0.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1378" published="2003-12-31" name="CVE-2003-1378" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:N)" CVSS_score="8.8" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.6" CVSS_base_score="8.8">
    <desc>
      <descript source="cve">Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11411" source="XF">outlook-codebase-execute-programs(11411)</ref>
      <ref url="http://www.securityfocus.com/bid/6923" source="BID">6923</ref>
      <ref url="http://www.securityfocus.com/archive/1/312929" source="BUGTRAQ">20030224 Re: O UT LO OK  E  XPRE SS 6 .00 : broken</ref>
      <ref url="http://www.securityfocus.com/archive/1/312910" source="BUGTRAQ">20030223 O UT LO OK  E  XPRE SS 6 .00 : broken</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sr1" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1379" published="2003-12-31" name="CVE-2003-1379" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6934" source="BID" patch="1">6934</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11419" source="XF">clarkconnect-clarkconnectd-info-disclosure(11419)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313080" source="BUGTRAQ">20030225 clarkconnect(d) information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="point_clark_networks" name="clarkconnect">
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1380" published="2003-12-31" name="CVE-2003-1380" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11347" source="XF">bisonftp-ls-view-files(11347)</ref>
      <ref url="http://www.securityfocus.com/bid/6873" source="BID">6873</ref>
      <ref url="http://www.securityfocus.com/archive/1/312032" source="BUGTRAQ">20030217 [immune advisory] Mulitple vulnerabilities found in BisonFTP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bisonftp" name="bisonftp_server_4">
        <vers num="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1381" published="2003-12-31" name="CVE-2003-1381" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11427" source="XF">amx-amxsay-format-string(11427)</ref>
      <ref url="http://www.securityfocus.com/bid/6968" source="BID">6968</ref>
      <ref url="http://www.securityfocus.com/archive/1/313273" source="BUGTRAQ">20030226 [VSA0308] Half-Life AMX-Mod remote (root) hole</ref>
      <ref url="http://securityreason.com/securityalert/3258" source="SREASON">3258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amxmod.net" name="amx_mod">
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1382" published="2003-12-31" name="CVE-2003-1382" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ISMail 1.4.3 and earlier allow remote attackers to execute arbitrary code via long domain names in (1) MAIL FROM or (2) RCPT TO fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11432" source="XF" patch="1">ismail-smtp-domain-bo(11432)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313363" source="BUGTRAQ" patch="1">20030227 ISMAIL (All Versions) Remote Buffer Overrun</ref>
      <ref url="http://www.securityfocus.com/bid/6972" source="BID">6972</ref>
      <ref url="http://securityreason.com/securityalert/3254" source="SREASON">3254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instantservers_inc." name="ismail">
        <vers num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1383" published="2003-12-31" name="CVE-2003-1383" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11443" source="XF">weberp-logicworks-ini-access(11443)</ref>
      <ref url="http://www.securityfocus.com/bid/6996" source="BID">6996</ref>
      <ref url="http://www.securityfocus.com/archive/1/313575" source="BUGTRAQ">20030301 web-erp 0.1.4 database access vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3257" source="SREASON">3257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicworks" name="web_erp">
        <vers prev="1" num="0.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1384" published="2003-12-31" name="CVE-2003-1384" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11448" source="XF">pylivredor-guestbook-xss(11448)</ref>
      <ref url="http://www.securityfocus.com/bid/6997" source="BID">6997</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004015.html" source="FULLDISC">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2003/03/msg00024.html" source="BUGTRAQ">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0102.html" source="VULNWATCH">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="py_software" name="py-livredor">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1385" published="2003-12-31" name="CVE-2003-1385" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11435" source="XF">invision-ipchat-file-include(11435)</ref>
      <ref url="http://www.securityfocus.com/bid/6976" source="BID">6976</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0099.html" source="VULNWATCH" adv="1">20030227 Invision Power Board (PHP)</ref>
      <ref url="http://www.osvdb.org/3357" source="OSVDB">3357</ref>
      <ref url="http://secunia.com/advisories/8182" source="SECUNIA">8182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1386" published="2003-12-31" name="CVE-2003-1386" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11440" source="XF">axis-messages-unauth-access(11440)</ref>
      <ref url="http://www.websec.org/adv/axis2400.txt.html" source="MISC">http://www.websec.org/adv/axis2400.txt.html</ref>
      <ref url="http://www.securityfocus.com/bid/6980" source="BID">6980</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0370.html" source="BUGTRAQ">20030325 Axis Video and Camera Servers - System log access and file access/overwrite via HTTP/CGI</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0377.html" source="BUGTRAQ">20030228 axis2400 webcams</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axis" name="2400_video_server">
        <vers num="2.0" />
        <vers num="2.20" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.33" />
      </prod>
      <prod vendor="axis" name="2401_video_server">
        <vers num="2.20" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1387" published="2003-12-31" name="CVE-2003-1387" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6811" source="BID" patch="1">6811</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11281" source="XF">opera-username-url-bo(11281)</ref>
      <ref url="http://www.securityfocus.com/archive/1/315794" source="BUGTRAQ">20030320 Opara 6.06 Released, Security-Hole Left</ref>
      <ref url="http://www.securityfocus.com/archive/1/311194" source="BUGTRAQ">20030209 Opera Username Buffer Overflow Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3253" source="SREASON">3253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1388" published="2003-12-31" name="CVE-2003-1388" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11740" source="XF">opera-long-url-bo(11740)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0116.html" source="BUGTRAQ">20030407 Unchecked Buffer in Opera 7.02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera">
        <vers num="7.02_build_2668" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1389" published="2003-12-31" name="CVE-2003-1389" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11294" source="XF">cryptobuddy-truncate-weak-security(11294)</ref>
      <ref url="http://www.securityfocus.com/bid/6815" source="BID">6815</ref>
      <ref url="http://www.securityfocus.com/archive/1/311176" source="BUGTRAQ">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_triangle_software" name="cryptobuddy">
        <vers num="1.0" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1390" published="2003-12-31" name="CVE-2003-1390" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11297" source="XF">cryptobuddy-plaintext-password-bytes(11297)</ref>
      <ref url="http://www.securityfocus.com/archive/1/311176" source="BUGTRAQ">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_triangle_software" name="cryptobuddy">
        <vers num="1.0" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1391" published="2003-12-31" name="CVE-2003-1391" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11298" source="XF">cryptobuddy-password-dictionary(11298)</ref>
      <ref url="http://www.securityfocus.com/bid/6810" source="BID">6810</ref>
      <ref url="http://www.securityfocus.com/archive/1/311176" source="BUGTRAQ">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_triangle_software" name="cryptobuddy">
        <vers num="1.0" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1392" published="2003-12-31" name="CVE-2003-1392" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11317" source="XF">cryptobuddy-password-information-disclosure(11317)</ref>
      <ref url="http://www.securityfocus.com/bid/6812" source="BID">6812</ref>
      <ref url="http://www.securityfocus.com/archive/1/311176" source="BUGTRAQ">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_triangle_software" name="cryptobuddy">
        <vers num="1.0" />
        <vers num="1.2" />
      </prod>
      <prod vendor="microsoft" name="all_windows">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1393" published="2003-12-31" name="CVE-2003-1393" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Buffer overflow in Gupta SQLBase 8.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long EXECUTE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11269" source="XF">sqlbase-execute-long-bo(11269)</ref>
      <ref url="http://www.securityfocus.com/bid/6808" source="BID">6808</ref>
      <ref url="http://www.securityfocus.com/archive/1/314379" source="BUGTRAQ">20030308 NII Advisory - Buffer Overflow in SQLBase (Revised)</ref>
      <ref url="http://www.securityfocus.com/archive/1/311159" source="BUGTRAQ">20030210 Buffer OverFlow in SQLBase 8.1.0 - NII Advisory</ref>
      <ref url="http://secunia.com/advisories/8023" source="SECUNIA" adv="1">8023</ref>
      <ref url="http://securityreason.com/securityalert/3256" source="SREASON">3256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gupta_technologies" name="sqlbase">
        <vers num="8.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1394" published="2003-12-31" name="CVE-2003-1394" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11447" source="XF">coffeecup-password-file-retrieval(11447)</ref>
      <ref url="http://www.securityfocus.com/bid/6995" source="BID">6995</ref>
      <ref url="http://www.securityfocus.com/archive/1/313580" source="BUGTRAQ">20030228 Easy obtaining User+Pass+More on CoffeeCup Password Wizard All Versions</ref>
      <ref url="http://securityreason.com/securityalert/3259" source="SREASON">3259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coffeecup_software" name="coffeecup_password_wizard">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1395" published="2003-12-31" name="CVE-2003-1395" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11228" source="XF">kazaa-automated-ad-bo(11228)</ref>
      <ref url="http://www.securityfocus.com/bid/6747" source="BID">6747</ref>
      <ref url="http://www.securityfocus.com/archive/1/309935" source="BUGTRAQ">20030202 Denial of service against Kazaa Media Desktop v2</ref>
      <ref url="http://securityreason.com/securityalert/3252" source="SREASON">3252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kazaa" name="kazaa_media_desktop">
        <vers num="2.0" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1396" published="2003-12-31" name="CVE-2003-1396" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7450" source="BID" patch="1">7450</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11894" source="XF">opera-file-extension-bo(11894)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0346.html" source="BUGTRAQ">20030427 [Opera 7/6] Long File Extension Heap Buffer Overrun Vulnerability in Download.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1397" published="2003-12-31" name="CVE-2003-1397" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11280" source="XF">opera-plugincontextshowdocument-bo(11280)</ref>
      <ref url="http://www.securityfocus.com/bid/6814" source="BID">6814</ref>
      <ref url="http://www.securityfocus.com/archive/1/311214" source="BUGTRAQ">20030210 Java-Applet crashes Opera 6.05 and 7.01</ref>
      <ref url="http://securityreason.com/securityalert/3255" source="SREASON">3255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1398" published="2003-12-31" name="CVE-2003-1398" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11306" source="XF">cisco-ios-icmp-redirect(11306)</ref>
      <ref url="http://www.securityfocus.com/bid/6823" source="BID">6823</ref>
      <ref url="http://securitytracker.com/id?1006075" source="SECTRACK">1006075</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0131.html" source="BUGTRAQ">20030211 Field Notice - IOS Accepts ICMP Redirects in Non-default Configuration Settings</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0s" />
        <vers num="12.0st" />
        <vers num="12.0t" />
        <vers num="12.1" />
        <vers num="12.1e" />
        <vers num="12.1t" />
        <vers num="12.2" />
        <vers num="12.2e" />
        <vers num="12.2f" />
        <vers num="12.2s" />
        <vers num="12.2t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1399" published="2003-12-31" name="CVE-2003-1399" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6914" source="BID" patch="1">6914</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11380" source="XF">linux-eject-information-disclosure(11380)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0278.html" source="BUGTRAQ">20030222 eject 2.0.10 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eject" name="eject">
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1400" published="2003-12-31" name="CVE-2003-1400" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11229" source="XF" patch="1">phpnuke-avatar-code-execution(11229)</ref>
      <ref url="http://www.securityfocus.com/bid/6750" source="BID">6750</ref>
      <ref url="http://www.securityfocus.com/archive/1/310115" source="BUGTRAQ">20030204 Re: PHP-Nuke Avatar Code injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/309959" source="BUGTRAQ">20030203 PHP-Nuke Avatar Code injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2a" />
        <vers num="5.3.1" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1401" published="2003-12-31" name="CVE-2003-1401" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11338" source="XF">phpboard-login-plaintext-passwords(11338)</ref>
      <ref url="http://www.securityfocus.com/bid/6862" source="BID">6862</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0069.html" source="VULNWATCH">20030215 php-Board (php)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_board" name="php_board">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1402" published="2003-12-31" name="CVE-2003-1402" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11341" source="XF">kietu-hit-file-include(11341)</ref>
      <ref url="http://www.securityfocus.com/bid/6863" source="BID">6863</ref>
      <ref url="http://secunia.com/advisories/10754" source="SECUNIA" adv="1">10754</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0071.html" source="VULNWATCH">20030215 Kietu ( PHP )</ref>
      <ref url="http://www.osvdb.org/3777" source="OSVDB">3777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kietu" name="kietu">
        <vers num="2.0" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1403" published="2003-12-31" name="CVE-2003-1403" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11353" source="XF">dotbr-foo-info-disclosure(11353)</ref>
      <ref url="http://www.securityfocus.com/bid/6864" source="BID">6864</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html" source="VULNWATCH">20030215 DotBr (PHP)</ref>
      <ref url="http://www.osvdb.org/5091" source="OSVDB">5091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotbr" name="botbr">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1404" published="2003-12-31" name="CVE-2003-1404" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11354" source="XF">dotbr-config-info-disclosure(11354)</ref>
      <ref url="http://www.securityfocus.com/bid/6865" source="BID">6865</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html" source="VULNWATCH">20030215 DotBr (PHP)</ref>
      <ref url="http://www.osvdb.org/5092" source="OSVDB">5092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotbr" name="botbr">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1405" published="2003-12-31" name="CVE-2003-1405" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11355" source="XF">dotbr-exec-execute-commands(11355)</ref>
      <ref url="http://www.securityfocus.com/bid/6867" source="BID">6867</ref>
      <ref url="http://www.securityfocus.com/bid/6866" source="BID">6866</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html" source="VULNWATCH">20030215 DotBr (PHP)</ref>
      <ref url="http://www.osvdb.org/5090" source="OSVDB">5090</ref>
      <ref url="http://www.osvdb.org/5089" source="OSVDB">5089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotbr" name="botbr">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1406" published="2003-12-31" name="CVE-2003-1406" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11342" source="XF">dform-header-file-include(11342)</ref>
      <ref url="http://www.securityfocus.com/bid/6879" source="BID">6879</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0072.html" source="VULNWATCH">20030216 D-Forum (PHP)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adalis_infomatique" name="d_forum">
        <vers num="1.0" />
        <vers num="1.10" />
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1407" published="2003-12-31" name="CVE-2003-1407" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11329" source="XF">win-cmd-cd-bo(11329)</ref>
      <ref url="http://www.securityfocus.com/bid/6829" source="BID">6829</ref>
      <ref url="http://www.securityfocus.com/archive/1/311359" source="BUGTRAQ">20030211 SECURITY.NNOV: Windows NT 4.0/2000 cmd.exe long path buffer overflow/DoS</ref>
      <ref url="http://securityreason.com/securityalert/3251" source="SREASON">3251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1408" published="2003-12-31" name="CVE-2003-1408" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11311" source="XF">lotus-domino-dot-file-download(11311)</ref>
      <ref url="http://www.securityfocus.com/bid/6841" source="BID">6841</ref>
      <ref url="http://www.securityfocus.com/archive/1/311806" source="BUGTRAQ">20030213 Re: Lotus Domino DOT Bug Allows for Source Code Viewing</ref>
      <ref url="http://www.securityfocus.com/archive/1/311660" source="BUGTRAQ">20030212 Lotus Domino DOT Bug Allows for Source Code Viewing</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_server">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1409" published="2003-12-31" name="CVE-2003-1409" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0049.html" source="BUGTRAQ" patch="1">20030204 TOPo 1.43 and prior - Path Disclosure (in.php, out.php)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11248" source="XF">topo-path-disclosure(11248)</ref>
      <ref url="http://www.securityfocus.com/bid/6768" source="BID">6768</ref>
      <ref url="http://secunia.com/advisories/8008" source="SECUNIA" adv="1">8008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ej3" name="topo">
        <vers num="1.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1410" published="2003-12-31" name="CVE-2003-1410" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11278" source="XF">cedric-email-file-include(11278)</ref>
      <ref url="http://www.securityfocus.com/bid/6818" source="BID">6818</ref>
      <ref url="http://www.securityfocus.com/archive/1/311173" source="BUGTRAQ">20030209 Cedric Email Reader (PHP)</ref>
      <ref url="http://www.osvdb.org/5487" source="OSVDB">5487</ref>
      <ref url="http://secunia.com/advisories/8024" source="SECUNIA">8024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isoca" name="cedric_email_reader">
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1411" published="2003-12-31" name="CVE-2003-1411" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11278" source="XF">cedric-email-file-include(11278)</ref>
      <ref url="http://www.securityfocus.com/bid/6820" source="BID">6820</ref>
      <ref url="http://www.securityfocus.com/archive/1/311173" source="BUGTRAQ">20030209 Cedric Email Reader (PHP)</ref>
      <ref url="http://www.osvdb.org/5900" source="OSVDB">5900</ref>
      <ref url="http://secunia.com/advisories/8024" source="SECUNIA">8024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isoca" name="cedric_email_reader">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1412" published="2003-12-31" name="CVE-2003-1412" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11408" source="XF">gosa-plugin-file-include(11408)</ref>
      <ref url="http://www.securityfocus.com/bid/6922" source="BID">6922</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003932.html" source="FULLDISC">20030223 GOnicus System Administrator php injection</ref>
      <ref url="http://www.securitytracker.com/id?1006162" source="SECTRACK">1006162</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/313282/30/25760/threaded" source="BUGTRAQ">20030224 GOnicus System Administrator php injection</ref>
      <ref url="http://secunia.com/advisories/8120" source="SECUNIA">8120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gonicus" name="gonicus_system_administration">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1413" published="2003-12-31" name="CVE-2003-1413" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11445" source="XF" patch="1">darwin-dotdot-file-existence(11445)</ref>
      <ref url="http://www.securityfocus.com/bid/6992" source="BID">6992</ref>
      <ref url="http://www.securityfocus.com/archive/1/313517" source="BUGTRAQ">20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3260" source="SREASON">3260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1414" published="2003-12-31" name="CVE-2003-1414" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename paramter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11446" source="XF" patch="1">darwin-dotdotdot-directory-traversal(11446)</ref>
      <ref url="http://www.securityfocus.com/bid/6990" source="BID">6990</ref>
      <ref url="http://www.securityfocus.com/archive/1/313517" source="BUGTRAQ">20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3260" source="SREASON">3260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1415" published="2003-12-31" name="CVE-2003-1415" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11345" source="XF">netcharts-chunked-encoding-bo(11345)</ref>
      <ref url="http://www.securityfocus.com/bid/6877" source="BID">6877</ref>
      <ref url="http://www.securityfocus.com/archive/1/312187" source="BUGTRAQ">20030218 [SecurityOffice] Netcharts XBRL Server v4.0.0 Information Leakage Vulnerability</ref>
      <ref url="http://secunia.com/advisories/8091" source="SECUNIA" adv="1">8091</ref>
      <ref url="http://securityreason.com/securityalert/3261" source="SREASON">3261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visual_mining" name="netcharts_xbrl_server">
        <vers num="4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1416" published="2003-12-31" name="CVE-2003-1416" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11346" source="XF">bisonftp-ls-cwd-dos(11346)</ref>
      <ref url="http://www.securityfocus.com/bid/6869" source="BID">6869</ref>
      <ref url="http://www.securityfocus.com/archive/1/312032" source="BUGTRAQ">20030217 [immune advisory] Mulitple vulnerabilities found in BisonFTP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bisonftp" name="bisonftp_server_4">
        <vers num="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1417" published="2003-12-31" name="CVE-2003-1417" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11422" source="XF">ncipher-duplicate-keys(11422)</ref>
      <ref url="http://www.securityfocus.com/bid/6927" source="BID">6927</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104619088801750&amp;w=2" source="BUGTRAQ">20030225 nCipher Advisory #7: Unexpected copies of imported software keys</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="support_software">
        <vers num="6.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1418" published="2003-12-31" name="CVE-2003-1418" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child proccess IDs (PID).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6943" source="BID" patch="1">6943</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11438" source="XF">apache-mime-information-disclosure(11438)</ref>
      <ref url="http://www.securityfocus.com/bid/6939" source="BID">6939</ref>
      <ref url="http://www.openbsd.org/errata32.html" source="OPENBSD">[3.2] 008: SECURITY FIX: February 25, 2003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1419" published="2003-12-31" name="CVE-2003-1419" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11444" source="XF">netscape-javascript-reformatdate-dos(11444)</ref>
      <ref url="http://www.securityfocus.com/bid/6959" source="BID">6959</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0338.html" source="BUGTRAQ">20030225 Re: Netscape 6/7 crashes by a simple stylesheet...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1420" published="2003-12-31" name="CVE-2003-1420" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6962" source="BID" patch="1">6962</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11423" source="XF">opera-automatic-redirection-xss(11423)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313216" source="BUGTRAQ">20030226 Secunia Research: Opera browser Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1421" published="2003-12-31" name="CVE-2003-1421" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6854" source="BID" patch="1">6854</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11340" source="XF">suckbot-modmysqllogger-dos(11340)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suckbot" name="suckbot">
        <vers num="0.006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1422" published="2003-12-31" name="CVE-2003-1422" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6876" source="BID" patch="1">6876</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11351" source="XF">syslinux-gain-privileges(11351)</ref>
      <ref url="http://syslinux.zytor.com/history.php" source="CONFIRM">http://syslinux.zytor.com/history.php</ref>
      <ref url="http://secunia.com/advisories/8077" source="SECUNIA" adv="1">8077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="syslinux">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1423" published="2003-12-31" name="CVE-2003-1423" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11358" source="XF">petitforum-liste-info-disclosure(11358)</ref>
      <ref url="http://securitytracker.com/id?1006117" source="SECTRACK">1006117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="petitforum" name="petitforum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1424" published="2003-12-31" name="CVE-2003-1424" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11359" source="XF">petitforum-message-auth-bypass(11359)</ref>
      <ref url="http://securitytracker.com/id?1006117" source="SECTRACK">1006117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="petitforum" name="petitforum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1425" published="2003-12-31" name="CVE-2003-1425" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11356" source="XF">cpanel-guestbook-command-execution(11356)</ref>
      <ref url="http://www.securityfocus.com/bid/6882" source="BID">6882</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html" source="VULNWATCH">20030218 Cpanel 5 and below remote command execution and local root vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1426" published="2003-12-31" name="CVE-2003-1426" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11357" source="XF">cpanel-scriptfilename-gain-privileges(11357)</ref>
      <ref url="http://www.securityfocus.com/bid/6885" source="BID">6885</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html" source="VULNWATCH">20030218 Cpanel 5 and below remote command execution and local root vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1427" published="2003-12-31" name="CVE-2003-1427" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg coniguration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11279" source="XF">netgear-fm114p-directory-traversal(11279)</ref>
      <ref url="http://www.securityfocus.com/bid/6807" source="BID">6807</ref>
      <ref url="http://www.securityfocus.com/archive/1/311160" source="BUGTRAQ">20030209 Bug in Netgear FM114P Wireless Router firmware</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="fm114p">
        <vers num="1.4_beta_release_17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1428" published="2003-12-31" name="CVE-2003-1428" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="4.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.5" CVSS_base_score="4.8">
    <desc>
      <descript source="cve">Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11284" source="XF">gallery-album-insecure-directory(11284)</ref>
      <ref url="http://www.securityfocus.com/bid/6809" source="BID">6809</ref>
      <ref url="http://www.securityfocus.com/archive/1/311161" source="BUGTRAQ">20030210 Gallery 1.3.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bharat_mediratta" name="gallery">
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1429" published="2003-12-31" name="CVE-2003-1429" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11364" source="XF">proxomitron-parameter-length-bo(11364)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0088.html" source="VULNWATCH">20030219 [SCSA-005] Proxomitron Naoko Long Path Buffer Overflow/DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proxomitron" name="proxomitron_naoko">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1430" published="2003-12-31" name="CVE-2003-1430" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11299" source="XF">ut-file-directory-traversal(11299)</ref>
      <ref url="http://www.securityfocus.com/bid/6775" source="BID">6775</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" source="BUGTRAQ">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" source="BUGTRAQ">20030205 Unreal engine: results of my research</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="226f" />
        <vers num="433" />
        <vers num="436" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1431" published="2003-12-31" name="CVE-2003-1431" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11301" source="XF">ut-url-memory-corruption(11301)</ref>
      <ref url="http://www.securityfocus.com/bid/6774" source="BID">6774</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" source="BUGTRAQ">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" source="BUGTRAQ">20030205 Unreal engine: results of my research</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="226f" />
        <vers num="433" />
        <vers num="436" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1432" published="2003-12-31" name="CVE-2003-1432" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12012" source="XF">ut-negative-udp-dos(12012)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11305" source="XF">ut-negative-memory-corruption(11305)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11302" source="XF">ut-packet-dos(11302)</ref>
      <ref url="http://www.securityfocus.com/bid/6772" source="BID">6772</ref>
      <ref url="http://www.securityfocus.com/bid/6770" source="BID">6770</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0142.html" source="BUGTRAQ">20030513 UT2003 client passive DoS exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" source="BUGTRAQ">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" source="BUGTRAQ">20030205 Unreal engine: results of my research</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="226f" />
        <vers num="433" />
        <vers num="436" />
      </prod>
      <prod vendor="epic_games" name="unreal_tournament_2003">
        <vers num="2199_linux" />
        <vers num="2199_win32" />
        <vers num="demo_version_2206_linux" />
        <vers num="demo_version_2206_win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1433" published="2003-12-31" name="CVE-2003-1433" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11304" source="XF">ut-join-request-dos(11304)</ref>
      <ref url="http://www.securityfocus.com/bid/6771" source="BID">6771</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html" source="BUGTRAQ">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html" source="BUGTRAQ">20030205 Unreal engine: results of my research</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="226f" />
        <vers num="433" />
        <vers num="436" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1434" published="2003-12-31" name="CVE-2003-1434" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6903" source="BID" patch="1">6903</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11374" source="XF">loginldap-password-bypass(11374)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0244.html" source="BUGTRAQ">20030220 login_ldap security announcement</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pete_werner" name="login_ldap">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1435" published="2003-12-31" name="CVE-2003-1435" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11375" source="XF">phpnuke-search-sql-injection(11375)</ref>
      <ref url="http://www.securityfocus.com/bid/6887" source="BID">6887</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0246.html" source="BUGTRAQ">20030220 PHPNuke SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="5.6" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1436" published="2003-12-31" name="CVE-2003-1436" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1006031" source="SECTRACK" patch="1">1006031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11217" source="XF">nukebrowser-php-file-include(11217)</ref>
      <ref url="http://www.securityfocus.com/bid/6731" source="BID">6731</ref>
      <ref url="http://secunia.com/advisories/7986" source="SECUNIA" adv="1">7986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crossnuke" name="nukebrowser">
        <vers num="2.1" />
        <vers num="2.11" />
        <vers num="2.20" />
        <vers num="2.3" />
        <vers num="2.41" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1437" published="2003-12-31" name="CVE-2003-1437" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp" source="BEA" patch="1" adv="1">BEA03-25.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11220" source="XF">weblogic-keystore-plaintext-passwords(11220)</ref>
      <ref url="http://www.securityfocus.com/bid/6719" source="BID">6719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1438" published="2003-12-31" name="CVE-2003-1438" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-26.01.jsp" source="BEA" patch="1">BEA03-26.01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11221" source="XF">weblogic-clustered-race-condition(11221)</ref>
      <ref url="http://www.securityfocus.com/bid/6717" source="BID">6717</ref>
      <ref url="http://www.securitytracker.com/id?1006018" source="SECTRACK">1006018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1439" published="2003-12-31" name="CVE-2003-1439" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11244" source="XF">silc-plaintext-account-information(11244)</ref>
      <ref url="http://www.securityfocus.com/bid/6743" source="BID">6743</ref>
      <ref url="http://www.securityfocus.com/archive/1/309775" source="BUGTRAQ">20030201 silc question - insecure memory</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/309941/30/26090/threaded" source="BUGTRAQ">20030201 Re: silc question - insecure memory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silc" name="secure_internet_live_conferencing">
        <vers num="0.9.11" />
        <vers num="0.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1440" published="2003-12-31" name="CVE-2003-1440" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6739" source="BID" patch="1">6739</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11247" source="XF">spamprobe-newlines-href-dos(11247)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137128" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=137128</ref>
      <ref url="http://secunia.com/advisories/7994" source="SECUNIA" adv="1">7994</ref>
      <ref url="http://www.securitytracker.com/id?1006038" source="SECTRACK">1006038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="burton_computer_corporation" name="spamprobe">
        <vers num="0.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1441" published="2003-12-31" name="CVE-2003-1441" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6799" source="BID" patch="1">6799</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11285" source="XF">posadis-dns-packet-dos(11285)</ref>
      <ref url="http://www.osvdb.org/3522" source="OSVDB">3522</ref>
      <ref url="http://secunia.com/advisories/8018" source="SECUNIA">8018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="posadis" name="posadis">
        <vers num="0.50.4" />
        <vers num="0.50.5" />
        <vers num="0.50.6" />
        <vers num="0.50.7" />
        <vers num="0.50.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1442" published="2003-12-31" name="CVE-2003-1442" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6824" source="BID" patch="1">6824</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11290" source="XF">ericsson-hm220dp-auth-bypass(11290)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104619331706574&amp;w=2" source="BUGTRAQ">20030225 RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0127.html" source="BUGTRAQ">20030211 Ericsson HM220dp ADSL modem Insecure Web Administration Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ericsson" name="hm220dp_adsl_modem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1443" published="2003-12-31" name="CVE-2003-1443" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11292" source="XF">kav-device-name-bypass(11292)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0130.html" source="BUGTRAQ">20030211 SECURITY.NNOV: Kaspersky Antivirus DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="4.0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1444" published="2003-12-31" name="CVE-2003-1444" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11291" source="XF">kav-long-path-dos(11291)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0130.html" source="BUGTRAQ">20030211 SECURITY.NNOV: Kaspersky Antivirus DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="4.0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1445" published="2003-12-31" name="CVE-2003-1445" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11293" source="XF">far-long-path-bo(11293)</ref>
      <ref url="http://www.securityfocus.com/bid/6822" source="BID">6822</ref>
      <ref url="http://www.securityfocus.com/archive/1/311334" source="BUGTRAQ">20030211 SECURITY.NNOV: Far buffer overflow</ref>
      <ref url="http://securityreason.com/securityalert/3281" source="SREASON">3281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rarlab" name="far_manager">
        <vers num="1.65" />
        <vers num="1.70_beta_1" />
        <vers num="1.70_beta_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1446" published="2003-12-31" name="CVE-2003-1446" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Buffer overflow in the save_into_file function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11382" source="XF">rogue-saveintofile-bo(11382)</ref>
      <ref url="http://www.securityfocus.com/bid/6912" source="BID">6912</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0260.html" source="BUGTRAQ">20030221 Rogue buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rogue" name="rogue">
        <vers num="5.2-2" />
        <vers num="985.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1447" published="2003-12-31" name="CVE-2003-1447" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11245" source="XF">websphere-xml-weak-encryption(11245)</ref>
      <ref url="http://www.securityfocus.com/bid/6758" source="BID">6758</ref>
      <ref url="http://www.securityfocus.com/archive/1/310796" source="BUGTRAQ">20030206 Re: Weak password protection in WebSphere 4.0.4 XML configuration export</ref>
      <ref url="http://www.securityfocus.com/archive/1/310118" source="BUGTRAQ">20030204 Weak password protection in WebSphere 4.0.4 XML configuration export</ref>
      <ref url="http://securityreason.com/securityalert/3277" source="SREASON">3277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="4.0.4" edition="" />
        <vers num="4.0.4" edition=":advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1448" published="2003-12-31" name="CVE-2003-1448" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11274" source="XF">win2k-netbios-continuation-dos(11274)</ref>
      <ref url="http://www.securityfocus.com/bid/6766" source="BID">6766</ref>
      <ref url="http://www.immunitysec.com/downloads/advantages_of_block_based_analysis.html" source="MISC">http://www.immunitysec.com/downloads/advantages_of_block_based_analysis.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1449" published="2003-12-31" name="CVE-2003-1449" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11295" source="XF">esafe-gateway-filter-bypass(11295)</ref>
      <ref url="http://www.securityfocus.com/bid/6787" source="BID">6787</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0088.html" source="BUGTRAQ">20030206 FW-1 NG FP3 Bug - Data flow problem when transferring large files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_knowledge_systems" name="esafe_gateway">
        <vers num="3.5.126.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1450" published="2003-12-31" name="CVE-2003-1450" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11363" source="XF">bitchx-irc-namreply-dos(11363)</ref>
      <ref url="http://www.securityfocus.com/bid/6880" source="BID">6880</ref>
      <ref url="http://www.securityfocus.com/archive/1/312133" source="BUGTRAQ">20030217 [argv] BitchX-353 Vulnerability</ref>
      <ref url="http://www.linuxsecurity.com/content/view/104622/104/" source="GENTOO">200302-11</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003850.html" source="FULLDISC">20030217 [argv] BitchX-353 Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3279" source="SREASON">3279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitchx" name="bitchx">
        <vers num="1.0_c16" />
        <vers num="1.0_c19" />
        <vers num="1.0_c20cvs" />
        <vers num="75p3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1451" published="2003-12-31" name="CVE-2003-1451" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11365" source="XF">nav-email-filename-bo(11365)</ref>
      <ref url="http://www.securityfocus.com/bid/6886" source="BID">6886</ref>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/61_e.html" source="MISC">http://www.lac.co.jp/security/english/snsadv_e/61_e.html</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-02/0233.html" source="BUGTRAQ">20030219 [SNS Advisory No.61] Symantec Norton AntiVirus 2002 Buffer Overflow Vulnerability</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1452" published="2003-12-31" name="CVE-2003-1452" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11877" source="XF">qpopper-poppassd-root-access(11877)</ref>
      <ref url="http://www.securityfocus.com/bid/7447" source="BID">7447</ref>
      <ref url="http://www.securityfocus.com/archive/1/319811" source="BUGTRAQ">20030428 Qpopper v4.0.x poppassd local root exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0047.html" source="VULNWATCH">20030429 [INetCop Security Advisory] Qpopper v4.0.x poppassd local root</ref>
      <ref url="http://securityreason.com/securityalert/3268" source="SREASON">3268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5_fc2" />
        <vers num="4.0_b14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1453" published="2003-12-31" name="CVE-2003-1453" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7434" source="BID" patch="1">7434</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11872" source="XF">xoops-mytextsanitizer-xss(11872)</ref>
      <ref url="http://www.securityfocus.com/archive/1/319715" source="BUGTRAQ">20030425 XOOPS MyTextSanitizer CSS 1.3x &amp; 2.x</ref>
      <ref url="http://securityreason.com/securityalert/3269" source="SREASON">3269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1454" published="2003-12-31" name="CVE-2003-1454" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11871" source="XF">invision-admin-plaintext-password(11871)</ref>
      <ref url="http://www.securityfocus.com/bid/7440" source="BID">7440</ref>
      <ref url="http://www.securityfocus.com/archive/1/319747" source="BUGTRAQ">20030425 Invision Power Board Plaintext Password Disclosure Vuln</ref>
      <ref url="http://securityreason.com/securityalert/3276" source="SREASON">3276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1455" published="2003-12-31" name="CVE-2003-1455" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7590" source="BID" patch="1">7590</ref>
      <ref url="http://www.securityfocus.com/bid/7582" source="BID" patch="1">7582</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=138437" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=138437</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12101" source="XF">poptop-launchbcrelay-pptpctrlc-bo(12101)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poptop" name="pptp_server">
        <vers num="1.1.4b1" />
        <vers num="1.1.4b2" />
        <vers num="1.1.4b3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1456" published="2003-12-31" name="CVE-2003-1456" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/319763" source="BUGTRAQ" patch="1">20030426 Album.pl Vulnerability - Remote Command Execution</ref>
      <ref url="http://perl.bobbitt.ca/yabbse/index.php?board=2;action=display;threadid=720" source="CONFIRM" patch="1">http://perl.bobbitt.ca/yabbse/index.php?board=2;action=display;threadid=720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11878" source="XF">albumpl-command-execution(11878)</ref>
      <ref url="http://www.securityfocus.com/bid/7444" source="BID">7444</ref>
      <ref url="http://securityreason.com/securityalert/3270" source="SREASON">3270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_bobbitt" name="album.pl">
        <vers prev="1" num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1457" published="2003-12-31" name="CVE-2003-1457" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11923" source="XF">comsuite-runasositron-backdoor-account(11923)</ref>
      <ref url="http://www.securityfocus.com/bid/7458" source="BID">7458</ref>
      <ref url="http://www.securityfocus.com/archive/1/319946" source="BUGTRAQ">20030429 Auerswald COMsuite/ Back Door</ref>
      <ref url="http://securityreason.com/securityalert/3282" source="SREASON">3282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="auerswald" name="comsuite_cti_controlcenter">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1458" published="2003-12-31" name="CVE-2003-1458" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12273" source="XF">ttcms-profile-sql-injection(12273)</ref>
      <ref url="http://www.securityfocus.com/bid/7543" source="BID">7543</ref>
      <ref url="http://www.securityfocus.com/archive/1/321000" source="BUGTRAQ">20030509 ttcms and ttforum exploits</ref>
      <ref url="http://securityreason.com/securityalert/3278" source="SREASON">3278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ttcms" name="ttcms">
        <vers num="2.2" />
      </prod>
      <prod vendor="ttcms" name="ttforum">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1459" published="2003-12-31" name="CVE-2003-1459" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12271" source="XF">ttcms-ttforum-file-include(12271)</ref>
      <ref url="http://www.securityfocus.com/bid/7542" source="BID">7542</ref>
      <ref url="http://www.securityfocus.com/archive/1/321000" source="BUGTRAQ">20030509 ttcms and ttforum exploits</ref>
      <ref url="http://securityreason.com/securityalert/3278" source="SREASON">3278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ttcms" name="ttcms">
        <vers num="2.2" />
      </prod>
      <prod vendor="ttcms" name="ttforum">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1460" published="2003-12-31" name="CVE-2003-1460" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7460" source="BID" patch="1">7460</ref>
      <ref url="http://www.boomerangsworld.de/worker/wchanges.php3?lang=en" source="CONFIRM">http://www.boomerangsworld.de/worker/wchanges.php3?lang=en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralf_hoffmann" name="worker_filemanager">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1461" published="2003-12-31" name="CVE-2003-1461" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument.  NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7489" source="BID" patch="1">7489</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11919" source="XF">hp-rwrite-bo(11919)</ref>
      <ref url="http://www.securityfocus.com/archive/1/320371" source="BUGTRAQ">20030503 rwrite buffer overflow in hp-ux</ref>
      <ref url="http://www.securityfocus.com/archive/1/320323" source="BUGTRAQ">20030502 HP-UX 11.0 /usr/lbin/rwrite</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4897" source="OVAL">oval:org.mitre.oval:def:4897</ref>
      <ref url="http://securityreason.com/securityalert/3283" source="SREASON">3283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1462" published="2003-12-31" name="CVE-2003-1462" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_survey 3.0.0 through 3.0.15-pre6 does not check whether a survey exists before creating a subdirectory for it, which allows remote attackers to cause a denial of service (disk consumption and possible crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7498" source="BID" patch="1">7498</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11861" source="XF">modsurvey-nonexistent-survey-dos(11861)</ref>
      <ref url="http://gathering.itm.mh.se/modsurvey/SA20030504.txt" source="CONFIRM">http://gathering.itm.mh.se/modsurvey/SA20030504.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0058.html" source="BUGTRAQ">20030504 Mod_Survey SYSBASE vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_survey" name="mod_survey">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14d" />
        <vers num="3.0.14e" />
        <vers num="3.0.15pre1" />
        <vers num="3.0.15pre2" />
        <vers num="3.0.15pre3" />
        <vers num="3.0.15pre4" />
        <vers num="3.0.15pre5" />
        <vers num="3.0.15pre6" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1463" published="2003-12-31" name="CVE-2003-1463" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11875" source="XF">webadmin-webadmindll-view-files(11875)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11874" source="XF">webadmin-webadmindll-path-disclosure(11874)</ref>
      <ref url="http://www.securityfocus.com/bid/7439" source="BID">7439</ref>
      <ref url="http://www.securityfocus.com/bid/7438" source="BID">7438</ref>
      <ref url="http://www.securityfocus.com/archive/1/319735" source="BUGTRAQ">20030425 Path disclosure and file access on WebAdmin</ref>
      <ref url="http://securityreason.com/securityalert/3286" source="SREASON">3286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1464" published="2003-12-31" name="CVE-2003-1464" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Short Message Service (SMS) message with a long image name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11950" source="XF">siemens-sms-image-bo(11950)</ref>
      <ref url="http://www.securityfocus.com/bid/7507" source="BID">7507</ref>
      <ref url="http://www.securityfocus.com/archive/1/320555" source="BUGTRAQ">20030506 Siemens Mobile Phone - Buffer Overflow</ref>
      <ref url="http://securityreason.com/securityalert/3287" source="SREASON">3287</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="m45">
        <vers num="" />
      </prod>
      <prod vendor="siemens" name="s45">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1465" published="2003-12-31" name="CVE-2003-1465" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download.php in Phorum 3.4 through 3.4.2 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7569" source="BID" patch="1">7569</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12482" source="XF">phorum-download-directory-traversal(12482)</ref>
      <ref url="http://www.securityfocus.com/archive/1/321310" source="BUGTRAQ">20030513 Phorum Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3288" source="SREASON">3288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1466" published="2003-12-31" name="CVE-2003-1466" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7581" source="BID" patch="1">7581</ref>
      <ref url="http://www.securityfocus.com/bid/7583" source="BID">7583</ref>
      <ref url="http://www.securityfocus.com/archive/1/321310" source="BUGTRAQ">20030513 Phorum Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3288" source="SREASON">3288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1467" published="2003-12-31" name="CVE-2003-1467" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7584" source="BID" patch="1">7584</ref>
      <ref url="http://www.securityfocus.com/bid/7573" source="BID" patch="1">7573</ref>
      <ref url="http://www.securityfocus.com/bid/7572" source="BID" patch="1">7572</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12502" source="XF">phorum-register-html-injection(12502)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12487" source="XF">phorum-multiple-xss(12487)</ref>
      <ref url="http://www.securityfocus.com/bid/7577" source="BID">7577</ref>
      <ref url="http://www.securityfocus.com/bid/7576" source="BID">7576</ref>
      <ref url="http://www.securityfocus.com/archive/1/321310" source="BUGTRAQ">20030513 Phorum Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3288" source="SREASON">3288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers prev="1" num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1468" published="2003-12-31" name="CVE-2003-1468" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12436" source="XF">phpnuke-weblinks-path-disclosure(12436)</ref>
      <ref url="http://www.securityfocus.com/bid/7589" source="BID">7589</ref>
      <ref url="http://www.securityfocus.com/archive/1/321313" source="BUGTRAQ">20030512 Re: Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1469" published="2003-12-31" name="CVE-2003-1469" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11879" source="XF">coldfusion-mx-path-disclosure(11879)</ref>
      <ref url="http://www.securityfocus.com/bid/7443" source="BID">7443</ref>
      <ref url="http://www.securityfocus.com/archive/1/319867" source="BUGTRAQ">20030426 NII Advisory - Path Disclosure in Cold Fusion MX Server</ref>
      <ref url="http://www.nii.co.in/vuln/pdmac.html" source="MISC">http://www.nii.co.in/vuln/pdmac.html</ref>
      <ref url="http://securityreason.com/securityalert/3307" source="SREASON">3307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="" edition=":developer" />
        <vers num="6.0" />
      </prod>
      <prod vendor="macromedia" name="coldfusion_professional">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1470" published="2003-12-31" name="CVE-2003-1470" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a CREATE command with a long mailbox name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11896" source="XF">mdaemon-imap-create-bo(11896)</ref>
      <ref url="http://www.securityfocus.com/bid/7446" source="BID">7446</ref>
      <ref url="http://www.securityfocus.com/archive/1/319879" source="BUGTRAQ">20030427 MDaemon SMTP/POP/IMAP server  =>v.6.7.5: IMAP buffer overflow</ref>
      <ref url="http://securityreason.com/securityalert/3296" source="SREASON">3296</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="6.7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1471" published="2003-12-31" name="CVE-2003-1471" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11882" source="XF">mdaemon-pop3-negative-dos(11882)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0359.html" source="BUGTRAQ">20030428 RE: MDaemon SMTP/POP/IMAP server: =>6.0.7: POP remote DoS</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2003/04/msg00364.html" source="BUGTRAQ">20030428 MDaemon SMTP/POP/IMAP server: =>6.0.7: POP remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers prev="1" num="6.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1472" published="2003-12-31" name="CVE-2003-1472" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11883" source="XF">3dftp-ftp-banner-bo(11883)</ref>
      <ref url="http://www.securityfocus.com/bid/7451" source="BID">7451</ref>
      <ref url="http://www.securityfocus.com/archive/1/319818" source="BUGTRAQ">20030428 Buffer overflow in 3D-ftp</ref>
      <ref url="http://securityreason.com/securityalert/3297" source="SREASON">3297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3d-ftp" name="3d-ftp">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1473" published="2003-12-31" name="CVE-2003-1473" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11978" source="XF">ltris-bo(11978)</ref>
      <ref url="http://www.securityfocus.com/bid/7537" source="BID">7537</ref>
      <ref url="http://www.securityfocus.com/archive/1/321001" source="BUGTRAQ">20030508 ltris-and-slashem-tty possible trouble</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html" source="FULLDISC">20030509 ltris-and-slashem-tty possible trouble</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lgames" name="ltris">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1474" published="2003-12-31" name="CVE-2003-1474" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/321001" source="BUGTRAQ">20030508 ltris-and-slashem-tty possible trouble</ref>
      <ref url="http://www.iss.net/security_center/static/11979.php" source="XF">slashem-tty-insecure-permissions(11979)</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html" source="FULLDISC">20030509 ltris-and-slashem-tty possible trouble</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="slashem-tty">
        <vers num="0.0.6e.4f.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1475" published="2003-12-31" name="CVE-2003-1475" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Netbus 1.5 through 1.7 allows more than one client to be connected at the same time, but only prompts the first connection for authentication, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11982" source="XF">netbus-password-authentication-bypass(11982)</ref>
      <ref url="http://www.securityfocus.com/bid/7538" source="BID">7538</ref>
      <ref url="http://www.securityfocus.com/archive/1/320980" source="BUGTRAQ">20030509 Netbus 1.x exploit</ref>
      <ref url="http://securityreason.com/securityalert/3289" source="SREASON">3289</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbus" name="netbus">
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1476" published="2003-12-31" name="CVE-2003-1476" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7556" source="BID">7556</ref>
      <ref url="http://www.cerberusftp.com/cerberus-releasenotes.htm#KnownIssues" source="CONFIRM">http://www.cerberusftp.com/cerberus-releasenotes.htm#KnownIssues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerberus" name="ftp_server">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1477" published="2003-12-31" name="CVE-2003-1477" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12052" source="XF" patch="1">mailsweeper-powerpoint-file-dos(12052)</ref>
      <ref url="http://www.securityfocus.com/bid/7562" source="BID">7562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper_for_smtp">
        <vers num="4.3.6" />
        <vers num="4.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1478" published="2003-12-31" name="CVE-2003-1478" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11971" source="XF">kde-konqueror-dos(11971)</ref>
      <ref url="http://www.securityfocus.com/bid/7486" source="BID">7486</ref>
      <ref url="http://www.securityfocus.com/archive/1/320266" source="BUGTRAQ">20030502 Re: April appeared to be a month of IE bugs. Here</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1479" published="2003-12-31" name="CVE-2003-1479" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and 1.02.535 allows remote attackers to inject arbitrary web script or HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11952" source="XF">webcamxp-multiple-xss(11952)</ref>
      <ref url="http://www.securityfocus.com/bid/7490" source="BID">7490</ref>
      <ref url="http://www.securityfocus.com/archive/1/320345" source="BUGTRAQ">20030502 Code Injection Vulnerabilities in WebcamXP Chat Feature</ref>
      <ref url="http://www.frame4.com/content/advisories/FSA-2003-002.txt" source="MISC">http://www.frame4.com/content/advisories/FSA-2003-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/3304" source="SREASON">3304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darkwet" name="webcam_xp">
        <vers num="1.02.432" />
        <vers num="1.02.535" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1480" published="2003-12-31" name="CVE-2003-1480" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7500" source="BID">7500</ref>
      <ref url="http://www.securiteam.com/tools/5WP031FA0U.html" source="MISC">http://www.securiteam.com/tools/5WP031FA0U.html</ref>
      <ref url="http://secunia.com/advisories/8753" source="SECUNIA" adv="1">8753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.20" />
        <vers num="3.20.32a" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.22.26" />
        <vers num="3.22.27" />
        <vers num="3.22.28" />
        <vers num="3.22.29" />
        <vers num="3.22.30" />
        <vers num="3.22.32" />
        <vers num="3.23.10" />
        <vers num="3.23.2" />
        <vers num="3.23.22" />
        <vers num="3.23.23" />
        <vers num="3.23.24" />
        <vers num="3.23.25" />
        <vers num="3.23.26" />
        <vers num="3.23.27" />
        <vers num="3.23.28" edition="gamma" />
        <vers num="3.23.29" />
        <vers num="3.23.3" />
        <vers num="3.23.30" />
        <vers num="3.23.31" />
        <vers num="3.23.32" />
        <vers num="3.23.33" />
        <vers num="3.23.34" />
        <vers num="3.23.35" />
        <vers num="3.23.36" />
        <vers num="3.23.37" />
        <vers num="3.23.38" />
        <vers num="3.23.39" />
        <vers num="3.23.4" />
        <vers num="3.23.40" />
        <vers num="3.23.41" />
        <vers num="3.23.42" />
        <vers num="3.23.43" />
        <vers num="3.23.44" />
        <vers num="3.23.45" />
        <vers num="3.23.46" />
        <vers num="3.23.47" />
        <vers num="3.23.48" />
        <vers num="3.23.49" />
        <vers num="3.23.5" />
        <vers num="3.23.50" />
        <vers num="3.23.51" />
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.53a" />
        <vers num="3.23.54" />
        <vers num="3.23.54a" />
        <vers num="3.23.55" />
        <vers num="3.23.56" />
        <vers num="3.23.8" />
        <vers num="3.23.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.5a" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1481" published="2003-12-31" name="CVE-2003-1481" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7501" source="BID" patch="1">7501</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11932" source="XF">communigate-pro-session-hijacking(11932)</ref>
      <ref url="http://www.securityfocus.com/archive/1/320438" source="BUGTRAQ">20030504 CommuniGatePro 4.0.6 [EXPLOIT]</ref>
      <ref url="http://securityreason.com/securityalert/3290" source="SREASON">3290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="3.1" />
        <vers num="3.2.4" />
        <vers num="3.2_b5" />
        <vers num="3.2_b7" />
        <vers num="3.3.2" />
        <vers num="3.3_b1" />
        <vers num="3.3_b2" />
        <vers num="3.4_b3" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.6" />
        <vers num="4.0_b2" />
        <vers num="4.0_b3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1482" published="2003-12-31" name="CVE-2003-1482" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7496" source="BID">7496</ref>
      <ref url="http://securitytracker.com/id?1006691" source="SECTRACK">1006691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="mn-500_wireless_base_station">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1483" published="2003-12-31" name="CVE-2003-1483" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12298" source="XF">flashfxp-weak-password-encryption(12298)</ref>
      <ref url="http://www.securityfocus.com/bid/7499" source="BID">7499</ref>
      <ref url="http://securitytracker.com/id?1006730" source="SECTRACK">1006730</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/flashfxp_decrypt.c" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/flashfxp_decrypt.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flashfxp" name="flashfxp">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1484" published="2003-12-31" name="CVE-2003-1484" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11946" source="XF">ie-anchorclick-dos(11946)</ref>
      <ref url="http://www.securityfocus.com/bid/7502" source="BID">7502</ref>
      <ref url="http://www.securityfocus.com/archive/1/320544" source="BUGTRAQ">20030505 Crash in Internet Explorer 6.0 Sp1</ref>
      <ref url="http://securityreason.com/securityalert/3292" source="SREASON">3292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1485" published="2003-12-31" name="CVE-2003-1485" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7568" source="BID" patch="1">7568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.6_sp1" />
        <vers num="4.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1486" published="2003-12-31" name="CVE-2003-1486" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7571" source="BID" patch="1">7571</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12499" source="XF">phorum-multiple-path-disclosure(12499)</ref>
      <ref url="http://www.securityfocus.com/archive/1/321310" source="BUGTRAQ">20030513 Phorum Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3288" source="SREASON">3288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1487" published="2003-12-31" name="CVE-2003-1487" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7579" source="BID" patch="1">7579</ref>
      <ref url="http://www.securityfocus.com/bid/7578" source="BID" patch="1">7578</ref>
      <ref url="http://www.securityfocus.com/bid/7574" source="BID" patch="1">7574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12500" source="XF">phorum-command-execution(12500)</ref>
      <ref url="http://www.securityfocus.com/archive/1/321310" source="BUGTRAQ">20030513 Phorum Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3288" source="SREASON">3288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1488" published="2003-12-31" name="CVE-2003-1488" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11886" source="XF">truegalerie-verifadmin-admin-access(11886)</ref>
      <ref url="http://www.securityfocus.com/bid/7427" source="BID">7427</ref>
      <ref url="http://secunia.com/advisories/8683" source="SECUNIA" adv="1">8683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vulnwatch&amp;m=105128431109082&amp;w=2" source="VULNWATCH">20030425 True Galerie 1.0 : Admin Access &amp; File Copy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truelogik" name="truegalerie">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1489" published="2003-12-31" name="CVE-2003-1489" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/8683" source="SECUNIA" adv="1">8683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vulnwatch&amp;m=105128431109082&amp;w=2" source="VULNWATCH">20030425 True Galerie 1.0 : Admin Access &amp; File Copy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truegalerie" name="truegalerie">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1490" published="2003-12-31" name="CVE-2003-1490" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11876" source="XF">sonicwallpro-http-post-dos(11876)</ref>
      <ref url="http://www.securityfocus.com/bid/7435" source="BID">7435</ref>
      <ref url="http://www.securityfocus.com/archive/1/319712" source="BUGTRAQ">20030424 SonicWall Pro DoS?</ref>
      <ref url="http://securityreason.com/securityalert/3291" source="SREASON">3291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicwall" name="pro100">
        <vers num="6.4.0.1" />
      </prod>
      <prod vendor="sonicwall" name="pro200">
        <vers num="6.4.0.1" />
      </prod>
      <prod vendor="sonicwall" name="pro300">
        <vers num="6.4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1491" published="2003-12-31" name="CVE-2003-1491" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11880" source="XF">kerio-pf-firewall-bypass(11880)</ref>
      <ref url="http://www.securityfocus.com/bid/7436" source="BID">7436</ref>
      <ref url="http://www.securiteam.com/securitynews/5FP0N1P9PI.html" source="MISC">http://www.securiteam.com/securitynews/5FP0N1P9PI.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/0352.html" source="FULLDISC">20030422 UDP bypassing in Kerio Firewall 2.1.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall">
        <vers num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1492" published="2003-12-31" name="CVE-2003-1492" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11924" source="XF">netscape-domain-obtain-info(11924)</ref>
      <ref url="http://www.securityfocus.com/bid/7456" source="BID">7456</ref>
      <ref url="http://www.securityfocus.com/archive/1/319919" source="BUGTRAQ">20030429 "netscape navigator" is cracked.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1493" published="2003-12-31" name="CVE-2003-1493" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (memory exhaustion) via crafted TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8859" source="BID" patch="1">8859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13467" source="XF">openview-nnm-packet-dos(13467)</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q4/0019.html" source="HP">HPSBUX0310-291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="5.0.1" />
        <vers num="6.0.1" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":hp_ux_10.x" />
        <vers num="6.1" edition=":solaris" />
        <vers num="6.1" edition=":hp_ux_11.x" />
        <vers num="6.10" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":hp_ux_10.x" />
        <vers num="6.2" edition=":hp_ux_11.x" />
        <vers num="6.2" edition=":solaris" />
        <vers num="6.2" edition=":nt_4.x_windows_2000" />
        <vers num="6.31" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":hp_ux_11.x" />
        <vers num="6.4" edition=":nt_4.x_windows_2000" />
        <vers num="6.4" edition=":solaris" />
        <vers num="6.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1494" published="2003-12-31" name="CVE-2003-1494" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8859" source="BID" patch="1">8859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13467" source="XF">openview-nnm-packet-dos(13467)</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q4/0019.html" source="HP">HPSBUX0310-291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.2" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1495" published="2003-12-31" name="CVE-2003-1495" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8878" source="BID" patch="1">8878</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13496" source="XF">hp-management-gain-privileges(13496)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_management_suite">
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="hp" name="insight_manager">
        <vers num="1.0" />
        <vers num="1.6" />
      </prod>
      <prod vendor="hp" name="remote_diagnostics_enabling_agent">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1496" published="2003-12-31" name="CVE-2003-1496" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13418" source="XF">tru64-dtmailpr-gain-privileges(13418)</ref>
      <ref url="http://www.securityfocus.com/bid/8813" source="BID">8813</ref>
      <ref url="http://www.securityfocus.com/advisories/5973" source="COMPAQ">SSRT3589</ref>
      <ref url="http://secunia.com/advisories/9990" source="SECUNIA">9990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="tru64">
        <vers num="4.0f" />
        <vers num="4.0f_pk6_bl17" />
        <vers num="4.0f_pk7_bl18" />
        <vers num="4.0f_pk8_bl22" />
        <vers num="4.0g" />
        <vers num="4.0g_pk3_bl17" />
        <vers num="4.0g_pk4_bl22" />
        <vers num="5.1" />
        <vers num="5.1_pk3_bl17" />
        <vers num="5.1_pk4_bl18" />
        <vers num="5.1_pk5_bl19" />
        <vers num="5.1_pk6_bl20" />
        <vers num="5.1a" />
        <vers num="5.1a_pk1_bl1" />
        <vers num="5.1a_pk2_bl2" />
        <vers num="5.1a_pk3_bl3" />
        <vers num="5.1a_pk4_bl21" />
        <vers num="5.1a_pk5_bl23" />
        <vers num="5.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1497" published="2003-12-31" name="CVE-2003-1497" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">Buffer overflow in the system log viewer of Linksys BEFSX41 1.44.3 allows remote attackers to cause a denial of service via an HTTP request with a long Log_Page_Num variable.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13436" source="XF" patch="1">linksys-etherfast-logpagenum-dos(13436)</ref>
      <ref url="http://www.securityfocus.com/bid/8834" source="BID">8834</ref>
      <ref url="http://www.securityfocus.com/archive/1/341309" source="BUGTRAQ">20031015 LinkSys EtherFast Router Denial of Service Attack</ref>
      <ref url="http://www.linksys.com/download/vertxt/befsx41_1453.txt" source="CONFIRM">http://www.linksys.com/download/vertxt/befsx41_1453.txt</ref>
      <ref url="http://securityreason.com/securityalert/3298" source="SREASON">3298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="befsx41">
        <vers num="1.43.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1498" published="2003-12-31" name="CVE-2003-1498" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8823" source="BID" patch="1">8823</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0173.html" source="BUGTRAQ" patch="1">20031014 Cross-Site Scripting Vulnerability in Wrensoft Zoom Search Engine</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13431" source="XF">zoom-search-xss(13431)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wrensoft" name="zoom_search_engine">
        <vers prev="1" num="2.0_build_1018" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1499" published="2003-12-31" name="CVE-2003-1499" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8850" source="BID" patch="1">8850</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13456" source="XF">bytehoard-dotdot-directory-traversal(13456)</ref>
      <ref url="http://www.securiteam.com/unixfocus/6L00L008KE.html" source="MISC">http://www.securiteam.com/unixfocus/6L00L008KE.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012430.html" source="FULLDISC">20031019 ByteHoard Directory Traversal Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0200.html" source="BUGTRAQ">20031019 ByteHoard Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bytehoard" name="bytehoard">
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1500" published="2003-12-31" name="CVE-2003-1500" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13457" source="XF">cpCommerce-functionsphp-file-include(13457)</ref>
      <ref url="http://www.securityfocus.com/bid/8851" source="BID">8851</ref>
      <ref url="http://www.securityfocus.com/archive/1/341757" source="BUGTRAQ">20031019 ZH2003-31SA (security advisory): file inclusion vulnerability in cpCommerce</ref>
      <ref url="http://www.securiteam.com/unixfocus/6H00E2K8KG.html" source="MISC">http://www.securiteam.com/unixfocus/6H00E2K8KG.html</ref>
      <ref url="http://cpcommerce.org/forums/index.php?board=2;action=display;threadid=864" source="CONFIRM">http://cpcommerce.org/forums/index.php?board=2;action=display;threadid=864</ref>
      <ref url="http://securityreason.com/securityalert/3301" source="SREASON">3301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpcommerce" name="cpcommerce">
        <vers num="0.5f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1501" published="2003-12-31" name="CVE-2003-1501" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13469" source="XF">gast-arbeiter-file-upload(13469)</ref>
      <ref url="http://www.securityfocus.com/bid/8858" source="BID">8858</ref>
      <ref url="http://www.securityfocus.com/archive/1/341870" source="BUGTRAQ">20031020 Gast Arbeiter Privilege Escalation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gast_arbeiter" name="gast_arbeiter">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1502" published="2003-12-31" name="CVE-2003-1502" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8822" source="BID">8822</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012043.html" source="FULLDISC">20031015 Mod-Throttle [was: client attacks server - XSS]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snert.com" name="mod_throttle">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1503" published="2003-12-31" name="CVE-2003-1503" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8825" source="BID" patch="1">8825</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13443" source="XF">aim-getfile-screenname-bo(13443)</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0059.html" source="NTBUGTRAQ">20031015 Buffer Overflow in AOL Instant Messager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="5.2.3292" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1504" published="2003-12-31" name="CVE-2003-1504" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13465" source="XF">goldlink-variables-gain-access(13465)</ref>
      <ref url="http://www.securityfocus.com/bid/8847" source="BID">8847</ref>
      <ref url="http://www.securityfocus.com/archive/1/341760" source="BUGTRAQ">20031018 Get admin level on Goldlink script v3.0</ref>
      <ref url="http://securityreason.com/securityalert/3302" source="SREASON">3302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goldscripts" name="goldlink">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1505" published="2003-12-31" name="CVE-2003-1505" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13809" source="XF">ie-scrollbarbasecolor-dos(13809)</ref>
      <ref url="http://www.securityfocus.com/bid/8874" source="BID">8874</ref>
      <ref url="http://www.securityfocus.com/archive/1/342010" source="BUGTRAQ">20031022 IE6 CSS-Crash</ref>
      <ref url="http://securityreason.com/securityalert/3295" source="SREASON">3295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1506" published="2003-12-31" name="CVE-2003-1506" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13507" source="XF">censornet-cgi-xss(13507)</ref>
      <ref url="http://www.securityfocus.com/bid/8876" source="BID">8876</ref>
      <ref url="http://www.securityfocus.com/archive/1/342577" source="BUGTRAQ">20031027 Re: CensorNet: Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/342551" source="BUGTRAQ">20031027 Re: CensorNet: Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/342160" source="BUGTRAQ">20031022 CensorNet: Cross Site Scripting Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3299" source="SREASON">3299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_barron" name="dansguardian">
        <vers num="3.0" />
        <vers num="3.1_r5" />
        <vers num="3.1_r6" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1507" published="2003-12-31" name="CVE-2003-1507" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13446" source="XF">wgsd-default-admin-account(13446)</ref>
      <ref url="http://www.securityfocus.com/bid/8837" source="BID">8837</ref>
      <ref url="http://www.securityfocus.com/archive/1/341329" source="BUGTRAQ">20031015 Few issues previously unpublished in English</ref>
      <ref url="http://securitytracker.com/id?1007924" source="SECTRACK">1007924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="planet_technology_corp" name="wgsd-1020">
        <vers num="" />
      </prod>
      <prod vendor="planet_technology_corp" name="wsw-2401">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1508" published="2003-12-31" name="CVE-2003-1508" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8880" source="BID">8880</ref>
      <ref url="http://www.securityfocus.com/archive/1/342179" source="BUGTRAQ">20031023 (Fw) : mIRC 6.12 (latest) DCC Exploit</ref>
      <ref url="http://www.irchelp.org/irchelp/mirc/exploit.html" source="CONFIRM">http://www.irchelp.org/irchelp/mirc/exploit.html</ref>
      <ref url="http://securityreason.com/securityalert/3303" source="SREASON">3303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirc" name="mirc">
        <vers num="6.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1509" published="2003-12-31" name="CVE-2003-1509" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embeding script in a temp file before the temp file is executed by the default web browser.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8839" source="BID" patch="1">8839</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13445" source="XF">realoneplayer-temporary-script-execution(13445)</ref>
      <ref url="http://service.real.com/help/faq/security/securityupdate_october2003.html" source="CONFIRM">http://service.real.com/help/faq/security/securityupdate_october2003.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="2.0" />
        <vers num="6.0.11.818" />
        <vers num="6.0.11.830" />
        <vers num="6.0.11.841" />
        <vers num="6.0.11.853" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1510" published="2003-12-31" name="CVE-2003-1510" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">TinyWeb 1.9 allows remote attackers to cause a denial of service (CPU consumption) via a ".%00." in an HTTP GET request to the cgi-bin directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13402" source="XF">tinyweb-httpget-dos(13402)</ref>
      <ref url="http://www.securityfocus.com/bid/8810" source="BID">8810</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6S0052K8LQ.html" source="MISC">http://www.securiteam.com/windowsntfocus/6S0052K8LQ.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rit_research_labs" name="tinyweb">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1511" published="2003-12-31" name="CVE-2003-1511" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8841" source="BID" patch="1">8841</ref>
      <ref url="http://www.securityfocus.com/archive/1/341452" source="BUGTRAQ">20031016 CSS Vulnerability in Bajie HTTP JServer</ref>
      <ref url="http://securityreason.com/securityalert/3306" source="SREASON">3306</ref>
      <ref url="http://secunia.com/advisories/10023" source="SECUNIA" adv="1">10023</ref>
      <ref url="http://www.geocities.com/gzhangx/websrv/docs/security.html" source="CONFIRM">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bajie" name="java_http_server">
        <vers num="0.95" edition="d" />
        <vers num="0.95" edition="zxc" />
        <vers num="0.95" edition="zxe" />
        <vers num="0.95" edition="zxe1" />
        <vers num="0.95" edition="zxv4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1512" published="2003-12-31" name="CVE-2003-1512" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8818" source="BID" patch="1">8818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="khaled_mardam-bey" name="mirc">
        <vers num="6.1" />
        <vers num="6.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1513" published="2003-12-31" name="CVE-2003-1513" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13460" source="XF" adv="1">resin-name-comment-xss(13460)</ref>
      <ref url="http://www.securityfocus.com/bid/8852" source="BID">8852</ref>
      <ref url="http://secunia.com/advisories/10031" source="SECUNIA" adv="1">10031</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012361.html" source="FULLDISC">20031019 Caucho Resin 2.x - Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="2.0" />
        <vers num="2.1.1" />
        <vers num="2.1.12" />
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1514" published="2003-12-31" name="CVE-2003-1514" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">eMule 0.29c allows remote attackers to cause a denial of service (crash) via a long password, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13464" source="XF">emule-long-password-dos(13464)</ref>
      <ref url="http://www.securityfocus.com/bid/8854" source="BID">8854</ref>
      <ref url="http://www.securityfocus.com/archive/1/341754" source="BUGTRAQ">20031019 eMule 2.2 [0.29c] - Web Control Panel - DOS(Denial Of Service)</ref>
      <ref url="http://securityreason.com/securityalert/3294" source="SREASON">3294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emule" name="emule">
        <vers num="0.29c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1515" published="2003-12-31" name="CVE-2003-1515" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Origo ASR-8100 ADSL Router 3.21 has an administration service running on port 254 that does not require a password, which allows remote attackers to cause a denial of service by restoring the factory defaults.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13463" source="XF">origo-default-settings-restore(13463)</ref>
      <ref url="http://www.securityfocus.com/bid/8855" source="BID">8855</ref>
      <ref url="http://www.securityfocus.com/archive/1/341752" source="BUGTRAQ">20031012 Origo ASR-8100 ADSL router remote factory reset</ref>
      <ref url="http://securityreason.com/securityalert/3300" source="SREASON">3300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="origo" name="asr-8100">
        <vers num="adsl_router_3.21" />
      </prod>
      <prod vendor="origo" name="asr-8400">
        <vers num="adsl_router" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1516" published="2003-12-31" name="CVE-2003-1516" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8857" source="BID">8857</ref>
      <ref url="http://www.securityfocus.com/archive/1/341815" source="BUGTRAQ">20031020 Cross Site Java applets</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_plug-in">
        <vers num="1.4.2_01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1517" published="2003-12-31" name="CVE-2003-1517" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13461" source="XF">dansie-cartpl-path-disclosure(13461)</ref>
      <ref url="http://www.securityfocus.com/bid/8860" source="BID">8860</ref>
      <ref url="http://www.securiteam.com/securitynews/6T00T008KG.html" source="MISC">http://www.securiteam.com/securitynews/6T00T008KG.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dansie" name="shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1518" published="2003-12-31" name="CVE-2003-1518" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8821" source="BID" patch="1">8821</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13428" source="XF">winsyslog-long-syslog-dos(13428)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6L00F158KE.html" source="MISC">http://www.securiteam.com/windowsntfocus/6L00F158KE.html</ref>
      <ref url="http://www.adiscon.com/Common/en/advisory/2003-09-15.asp" source="CONFIRM">http://www.adiscon.com/Common/en/advisory/2003-09-15.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adiscon" name="winsyslog">
        <vers num="4.21_sp1" />
        <vers num="5.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1519" published="2003-12-31" name="CVE-2003-1519" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13452" source="XF">vívísimo-clustering-engine-xss(13452)</ref>
      <ref url="http://www.securityfocus.com/bid/8862" source="BID">8862</ref>
      <ref url="http://securitytracker.com/id?1007955" source="SECTRACK">1007955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vivisimo" name="clustering_engine">
        <vers num="0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1520" published="2003-12-31" name="CVE-2003-1520" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8863" source="BID" patch="1">8863</ref>
      <ref url="http://www.securityfocus.com/archive/1/341908" source="BUGTRAQ" patch="1">20031021 SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version</ref>
      <ref url="http://securityreason.com/securityalert/3293" source="SREASON" patch="1">3293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuzzymonkey" name="myclassifieds">
        <vers num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1521" published="2003-12-31" name="CVE-2003-1521" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8867" source="BID">8867</ref>
      <ref url="http://www.securityfocus.com/archive/1/341943" source="BUGTRAQ">20031021 IE6 &amp; Java 1.4.2_02 applet: Hardware stress on floppy drive</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_plug-in">
        <vers num="1.4" />
        <vers num="1.4.2" />
        <vers num="1.4.2_01" />
        <vers num="1.4.2_02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1522" published="2003-12-31" name="CVE-2003-1522" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8869" source="BID">8869</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6S00S008KW.html" source="MISC">http://www.securiteam.com/windowsntfocus/6S00S008KW.html</ref>
      <ref url="http://www.pscs.co.uk/products/vpop3/whatsnew.html" source="CONFIRM">http://www.pscs.co.uk/products/vpop3/whatsnew.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pscs" name="vpop3_web_mail_server">
        <vers num="2.0e" />
        <vers num="2.0f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1523" published="2003-12-31" name="CVE-2003-1523" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8829" source="BID" patch="1">8829</ref>
      <ref url="http://secunia.com/advisories/10001" source="SECUNIA" adv="1">10001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbmail" name="dbmail">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1524" published="2003-12-31" name="CVE-2003-1524" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:N)" CVSS_score="6.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.4" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13490" source="XF">pgpdisk-obtain-information(13490)</ref>
      <ref url="http://www.securityfocus.com/bid/8870" source="BID">8870</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6M00L0K8KI.html" source="MISC">http://www.securiteam.com/windowsntfocus/6M00L0K8KI.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgpi" name="pgpdisk">
        <vers num="6.0.2i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1525" published="2003-12-31" name="CVE-2003-1525" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13498" source="XF">myphotogallery-unknown-vulnerabilities(13498)</ref>
      <ref url="http://www.securityfocus.com/bid/8872" source="BID">8872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_photo_gallery" name="my_photo_gallery">
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1526" published="2003-12-31" name="CVE-2003-1526" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8848" source="BID">8848</ref>
      <ref url="http://www.securityfocus.com/archive/1/341743" source="BUGTRAQ">20031018 PHP-Nuke Path Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1527" published="2003-12-31" name="CVE-2003-1527" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/5917" source="BID">5917</ref>
      <ref url="http://www.iss.net/security_center/static/10314.php" source="XF">firewall-autoblock-spoofing-dos(10314)</ref>
      <ref url="http://online.securityfocus.com/archive/1/294411" source="BUGTRAQ">20021008 Multiple Vendor PC firewall remote denial of services Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="internet_security_systems_blackice_defender">
        <vers num="2.9cap" />
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.5.cdf" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1528" published="2003-12-31" name="CVE-2003-1528" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008801" source="SECTRACK">1008801</ref>
      <ref url="http://www.securityfocus.com/bid/9446" source="BID">9446</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/350237/30/21640/threaded" source="BUGTRAQ">20040119 Networker 6.0 - possible symlink attack</ref>
      <ref url="http://securityreason.com/securityalert/3353" source="SREASON">3353</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="siemens_networker">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1529" published="2003-12-31" name="CVE-2003-1529" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11623" source="XF">jwalk-dotdot-directory-traversal(11623)</ref>
      <ref url="http://www.securitytracker.com/id?1006378" source="SECTRACK">1006378</ref>
      <ref url="http://www.securityfocus.com/bid/7160" source="BID">7160</ref>
      <ref url="http://www.osvdb.org/4927" source="OSVDB">4927</ref>
      <ref url="http://secunia.com/advisories/8411" source="SECUNIA" adv="1">8411</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0357.html" source="BUGTRAQ">20030325 IRM 005: JWalk Application Server Version 3.2c9 Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seagull_software_systems" name="j_walk_application_server">
        <vers num="3.2c9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1530" published="2003-12-31" name="CVE-2003-1530" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6634" source="BID" patch="1">6634</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307212/30/26300/threaded" source="BUGTRAQ">20030117 phpBB SQL Injection vulnerability</ref>
      <ref url="http://www.osvdb.org/4277" source="OSVDB">4277</ref>
      <ref url="http://secunia.com/advisories/7887/" source="SECUNIA" adv="1">7887</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html" source="BUGTRAQ">20030116 phpBB SQL Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb" name="phpbb">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1531" published="2003-12-31" name="CVE-2003-1531" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11638" source="XF">ceilidh-textcgi-xss(11638)</ref>
      <ref url="http://www.securitytracker.com/id?1006391" source="SECTRACK">1006391</ref>
      <ref url="http://www.securityfocus.com/bid/7214" source="BID">7214</ref>
      <ref url="http://secunia.com/advisories/8456" source="SECUNIA">8456</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=104878375423320&amp;w=2" source="BUGTRAQ">20030327 [SCSA-013] Cross Site Scripting vulnerability in testcgi.exe</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lilikoi" name="ceilidh">
        <vers prev="1" num="2.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1532" published="2003-12-31" name="CVE-2003-1532" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1006030" source="SECTRACK">1006030</ref>
      <ref url="http://www.securityfocus.com/bid/6746" source="BID">6746</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/309921/30/26090/threaded" source="BUGTRAQ">20030203 phpMyShop (php)</ref>
      <ref url="http://securityreason.com/securityalert/3348" source="SREASON">3348</ref>
      <ref url="http://secunia.com/advisories/7990" source="SECUNIA">7990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="julien_desaunay" name="phpmyshop">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1533" published="2003-12-31" name="CVE-2003-1533" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1005948" source="SECTRACK">1005948</ref>
      <ref url="http://www.securityfocus.com/bid/6594" source="BID">6594</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307224/30/26300/threaded" source="BUGTRAQ">20030113 phpPass (PHP)</ref>
      <ref url="http://securityreason.com/securityalert/3349" source="SREASON">3349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phppass" name="phppass">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1534" published="2003-12-31" name="CVE-2003-1534" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1006412" source="SECTRACK">1006412</ref>
      <ref url="http://www.securityfocus.com/bid/7233" source="BID">7233</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316745/30/25280/threaded" source="BUGTRAQ">20030329 Justice Guestbook 1.3 vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3347" source="SREASON">3347</ref>
      <ref url="http://secunia.com/advisories/8475" source="SECUNIA" adv="1">8475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justice_media" name="guestbook">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1535" published="2003-12-31" name="CVE-2003-1535" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1006412" source="SECTRACK">1006412</ref>
      <ref url="http://www.securityfocus.com/bid/7234" source="BID">7234</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316745/30/25280/threaded" source="BUGTRAQ">20030329 Justice Guestbook 1.3 vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3347" source="SREASON">3347</ref>
      <ref url="http://secunia.com/advisories/8475" source="SECUNIA" adv="1">8475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justice_media" name="guestbook">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1536" published="2003-12-31" name="CVE-2003-1536" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11602" source="XF">dcpportal-search-calendar-xss(11602)</ref>
      <ref url="http://www.securityfocus.com/bid/7144" source="BID">7144</ref>
      <ref url="http://www.securityfocus.com/bid/7141" source="BID">7141</ref>
      <ref url="http://www.osvdb.org/7022" source="OSVDB">7022</ref>
      <ref url="http://www.osvdb.org/7021" source="OSVDB">7021</ref>
      <ref url="http://secunia.com/advisories/8358" source="SECUNIA" adv="1">8358</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html" source="BUGTRAQ">20030318 Some XSS vulns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcp-portal" name="dcp-portal">
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1537" published="2003-12-31" name="CVE-2003-1537" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0117.html" source="VULNWATCH">20030309 Postnuke v 0.723 SQL injection and directory traversing</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers prev="1" num="0.723" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1538" published="2003-12-31" name="CVE-2003-1538" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1005954" source="SECTRACK" patch="1">1005954</ref>
      <ref url="http://secunia.com/advisories/7906" source="SECUNIA" patch="1" adv="1">7906</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_005_susehelp.html" source="SUSE">SUSE-SA:2003:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux_openexchange_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="office_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1539" published="2003-12-31" name="CVE-2003-1539" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7035" source="BID" patch="1">7035</ref>
      <ref url="http://secunia.com/advisories/8257" source="SECUNIA" patch="1" adv="1">8257</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=695597&amp;group_id=60333&amp;atid=493842" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=695597&amp;group_id=60333&amp;atid=493842</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=144274" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=144274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onedotoh" name="simple_file_manager">
        <vers prev="1" num="0.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1540" published="2003-12-31" name="CVE-2003-1540" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11571" source="XF">wf-chat-plaintext-passwords(11571)</ref>
      <ref url="http://www.securityfocus.com/bid/7147" source="BID">7147</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315583/30/25430/threaded" source="BUGTRAQ">20030319 WF-Chat</ref>
      <ref url="http://securitytracker.com/id?1006352" source="SECTRACK">1006352</ref>
      <ref url="http://secunia.com/advisories/8396" source="SECUNIA">8396</ref>
      <ref url="http://securityreason.com/securityalert/3645" source="SREASON">3645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wfchat" name="wfchat">
        <vers num="1.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1541" published="2003-12-31" name="CVE-2003-1541" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11609" source="XF">guestbooktr3a-plaintext-password-disclosure(11609)</ref>
      <ref url="http://www.securitytracker.com/id?1006360" source="SECTRACK">1006360</ref>
      <ref url="http://www.securityfocus.com/bid/7167" source="BID">7167</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315895/30/25400/threaded" source="BUGTRAQ">20030321 Guestbook tr3.a</ref>
      <ref url="http://secunia.com/advisories/8392" source="SECUNIA">8392</ref>
      <ref url="http://securityreason.com/securityalert/3653" source="SREASON">3653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="planetmoon" name="guestbook">
        <vers num="tr3.a.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1542" published="2003-12-31" name="CVE-2003-1542" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://platon.sk/projects/release_view_page.php?release_id=2" source="CONFIRM" patch="1">http://platon.sk/projects/release_view_page.php?release_id=2</ref>
      <ref url="http://www.securityfocus.com/bid/6933" source="BID">6933</ref>
      <ref url="http://secunia.com/advisories/8183" source="SECUNIA" adv="1">8183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ondrej_jombik" name="phpwebfilemanager">
        <vers prev="1" num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1543" published="2003-12-31" name="CVE-2003-1543" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11687" source="XF">bajie-error-message-xss(11687)</ref>
      <ref url="http://www.securityfocus.com/bid/7344" source="BID">7344</ref>
      <ref url="http://www.securiteam.com/securitynews/5LP10009FC.html" source="MISC">http://www.securiteam.com/securitynews/5LP10009FC.html</ref>
      <ref url="http://www.lucaercoli.it/advs/bajie.txt" source="MISC">http://www.lucaercoli.it/advs/bajie.txt</ref>
      <ref url="http://www.geocities.com/gzhangx/websrv/docs/security.html" source="MISC">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
      <ref url="http://securitytracker.com/id?1006428" source="SECTRACK">1006428</ref>
      <ref url="http://secunia.com/advisories/8477" source="SECUNIA" adv="1">8477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bajie" name="java_http_server">
        <vers num="0.95" edition="zxc" />
        <vers num="0.95" edition="zxe" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1544" published="2003-12-31" name="CVE-2003-1544" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11816" source="XF">win2k-terminal-msgina-permissions(11816)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11141" source="XF">win2k-terminal-msgina-dos(11141)</ref>
      <ref url="http://www.securitytracker.com/id?1005986" source="SECTRACK">1005986</ref>
      <ref url="http://www.securityfocus.com/bid/6672" source="BID">6672</ref>
      <ref url="http://www.securityfocus.com/archive/1/308164" source="BUGTRAQ">20030124 RE: DoS attack on Windows 2000 Terminal Server</ref>
      <ref url="http://www.securityfocus.com/archive/1/308059" source="BUGTRAQ">20030123 DoS attack on Windows 2000 Terminal Server</ref>
      <ref url="http://support.microsoft.com/kb/815225/en-us" source="MSKB">815225</ref>
      <ref url="http://secunia.com/advisories/7959" source="SECUNIA" adv="1">7959</ref>
      <ref url="http://securityreason.com/securityalert/3654" source="SREASON">3654</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp3" />
        <vers prev="1" num="" edition="sp3:adv_srv" />
        <vers prev="1" num="" edition="sp3:srv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1545" published="2003-12-31" name="CVE-2003-1545" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter.  NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1006377" source="SECTRACK">1006377</ref>
      <ref url="http://www.securityfocus.com/bid/7191" source="BID">7191</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316585/30/25310/threaded" source="BUGTRAQ">20030327 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316209/30/25340/threaded" source="BUGTRAQ">20030325 Re: PHPNuke viewpage.php and another SQL injections</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316179/30/25340/threaded" source="BUGTRAQ">20030325 PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref url="http://www.securityfocus.com/archive/1/316341/30/25310/threaded" source="BUGTRAQ">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref url="http://www.securityfocus.com/archive/1/316327/30/25340/threaded" source="BUGTRAQ">20030326 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref url="http://www.securityfocus.com/archive/1/316233/30/25340/threaded" source="BUGTRAQ">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref url="http://www.securityfocus.com/archive/1/316198/30/25340/threaded" source="BUGTRAQ">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukestyles" name="viewpage">
        <vers num="" />
      </prod>
      <prod vendor="phpnuke" name="nukestyles_viewpage_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1546" published="2003-12-31" name="CVE-2003-1546" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11540" source="XF">filebased-guestbook-gbook-xss(11540)</ref>
      <ref url="http://www.securitytracker.com/id?1006289" source="SECTRACK">1006289</ref>
      <ref url="http://www.securityfocus.com/bid/7104" source="BID">7104</ref>
      <ref url="http://secunia.com/advisories/8317" source="SECUNIA" adv="1">8317</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0219.html" source="BUGTRAQ">20030314 Guestbook v1.1.3 CSS Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filebased" name="guestbook">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1547" published="2003-12-31" name="CVE-2003-1547" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11675" source="XF">phpnuke-blockforums-subject-xss(11675)</ref>
      <ref url="http://www.securityfocus.com/bid/7248" source="BID">7248</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317230/30/25220/threaded" source="BUGTRAQ">20030401 Re: PHP-Nuke block-Forums.php subject vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316925/30/25250/threaded" source="BUGTRAQ">20030331 PHP-Nuke block-Forums.php subject vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3718" source="SREASON">3718</ref>
      <ref url="http://secunia.com/advisories/8478" source="SECUNIA" adv="1">8478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1548" published="2003-12-31" name="CVE-2003-1548" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11556" source="XF">myabracadaweb-index-path-disclosure(11556)</ref>
      <ref url="http://www.securitytracker.com/id?1006308" source="SECTRACK">1006308</ref>
      <ref url="http://www.securityfocus.com/bid/7126" source="BID">7126</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315317/30/25460/threaded" source="BUGTRAQ">20030317 [SCSA-010] Path Disclosure &amp; Cross Site Scripting Vulnerability in MyABraCaDaWeb</ref>
      <ref url="http://securityreason.com/securityalert/3717" source="SREASON">3717</ref>
      <ref url="http://secunia.com/advisories/8320" source="SECUNIA" adv="1">8320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myabracadaweb" name="myabracadaweb">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1549" published="2003-12-31" name="CVE-2003-1549" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11557" source="XF">myabracadaweb-index-makw-xss(11557)</ref>
      <ref url="http://www.securitytracker.com/id?1006308" source="SECTRACK">1006308</ref>
      <ref url="http://www.securityfocus.com/bid/7127" source="BID">7127</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315317/30/25460/threaded" source="BUGTRAQ">20030317 [SCSA-010] Path Disclosure &amp; Cross Site Scripting Vulnerability in MyABraCaDaWeb</ref>
      <ref url="http://securityreason.com/securityalert/3717" source="SREASON">3717</ref>
      <ref url="http://secunia.com/advisories/8320" source="SECUNIA" adv="1">8320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myabracadaweb" name="myabracadaweb">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1550" published="2003-12-31" name="CVE-2003-1550" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11587" source="XF">xoops-xoopsoption-path-disclosure(11587)</ref>
      <ref url="http://www.securityfocus.com/bid/7149" source="BID">7149</ref>
      <ref url="http://secunia.com/advisories/8353" source="SECUNIA" adv="1">8353</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=104887510828106&amp;w=2" source="BUGTRAQ">20030328 Re: [SCSA-011] Path Disclosure Vulnerability in XOOPS</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=104820295115420&amp;w=2" source="BUGTRAQ">20030320 [SCSA-011] Path Disclosure Vulnerability in XOOPS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1551" published="2003-12-31" name="CVE-2003-1551" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11394" source="XF">groupwise-script-execution(11394)</ref>
      <ref url="http://www.securitytracker.com/id?1006171" source="SECTRACK">1006171</ref>
      <ref url="http://www.securityfocus.com/bid/6896" source="BID">6896</ref>
      <ref url="http://secunia.com/advisories/8133" source="SECUNIA" adv="1">8133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers prev="1" num="6.0_sp3" edition="revision_e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1552" published="2003-12-31" name="CVE-2003-1552" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11467" source="XF">uploader-uploads-file-upload(11467)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/313819/30/25640/threaded" source="BUGTRAQ">20030304 uploader.php script</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/313787/30/25670/threaded" source="BUGTRAQ">20030304 uploader.php vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graeme" name="uploader">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1553" published="2003-12-31" name="CVE-2003-1553" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11572" source="XF">sips-user-obtain-information(11572)</ref>
      <ref url="http://www.securityfocus.com/bid/7134" source="BID">7134</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315504/30/25460/threaded" source="BUGTRAQ">20030318 SIPS (PHP)</ref>
      <ref url="http://securityreason.com/securityalert/3780" source="SREASON">3780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sips" name="sips">
        <vers num="0.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1554" published="2003-12-31" name="CVE-2003-1554" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11658" source="XF">scozbook-add-xss(11658)</ref>
      <ref url="http://www.securitytracker.com/id?1006413" source="SECTRACK">1006413</ref>
      <ref url="http://www.securityfocus.com/bid/7235" source="BID">7235</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316747/30/25280/threaded" source="BUGTRAQ">20030329 ScozBook BETA 1.1 vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/8476" source="SECUNIA" adv="1">8476</ref>
      <ref url="http://securityreason.com/securityalert/3781" source="SREASON">3781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scoznet" name="scozbook">
        <vers num="1.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1555" published="2003-12-31" name="CVE-2003-1555" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11659" source="XF">scozbook-view-path-disclosure(11659)</ref>
      <ref url="http://www.securitytracker.com/id?1006413" source="SECTRACK">1006413</ref>
      <ref url="http://www.securityfocus.com/bid/7236" source="BID">7236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316747/30/25280/threaded" source="BUGTRAQ">20030329 ScozBook BETA 1.1 vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/8476" source="SECUNIA">8476</ref>
      <ref url="http://securityreason.com/securityalert/3781" source="SREASON">3781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scoznet" name="scozbook">
        <vers num="1.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1556" published="2003-12-31" name="CVE-2003-1556" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7237" source="BID">7237</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316764/30/25250/threaded" source="BUGTRAQ">20030329 CGI-City's CCGuestBook Script Injection Vulns</ref>
      <ref url="http://securityreason.com/securityalert/3796" source="SREASON">3796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_city" name="cc_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1557" published="2003-12-31" name="CVE-2003-1557" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6679" source="BID" patch="1">6679</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11154" source="XF">spamassassin-spamc-offbyone-bo(11154)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/310212/30/26030/threaded" source="BUGTRAQ">20030204 Re: GLSA: Mail-SpamAssasin</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/309912/30/26090/threaded" source="GENTOO">GLSA-200302-01</ref>
      <ref url="http://secunia.com/advisories/7983" source="SECUNIA" adv="1">7983</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=104342896818777&amp;w=2" source="BUGTRAQ">20030123 SpamAssassin / spamc+BSMTP remote buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spamassassin" name="spamassassin">
        <vers num="2.40" />
        <vers num="2.41" />
        <vers num="2.42" />
        <vers num="2.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1558" published="2003-12-31" name="CVE-2003-1558" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in httpd.c of fnord 1.6 allows remote attackers to create a denial of service (crash) and possibly execute arbitrary code via a long CGI request passed to the do_cgi function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6635" source="BID" patch="1">6635</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11121" source="XF">fnord-httpdc-cgi-bo(11121)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307400/30/26270/threaded" source="BUGTRAQ">20030117 GLSA: fnord</ref>
      <ref url="http://www.fefe.de/fnord/" source="CONFIRM">http://www.fefe.de/fnord/</ref>
      <ref url="http://secunia.com/advisories/7893" source="SECUNIA" adv="1">7893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fefe" name="fnord">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1559" published="2003-12-31" name="CVE-2003-1559" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</descript>
    </desc>
    <impacts>
      <impact source="nvd">The only versions confirmed with this vulnerability are the ones listed in the CPE entry.  Other IE Versions may, and probably are, affected but have not been confirmed yet.</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9295" source="BID">9295</ref>
      <ref url="http://www.securityfocus.com/archive/1/348574" source="BUGTRAQ">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
      <ref url="http://www.securityfocus.com/archive/1/348360" source="BUGTRAQ">20031224 IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
      <ref url="http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html" source="MISC">http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html</ref>
      <ref url="http://securityreason.com/securityalert/3989" source="SREASON">3989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.22" />
        <vers num="5.5" />
        <vers num="6" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1560" published="2003-12-31" name="CVE-2003-1560" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/348574" source="BUGTRAQ">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
      <ref url="http://securityreason.com/securityalert/4004" source="SREASON">4004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1561" published="2003-12-31" name="CVE-2003-1561" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/348574" source="BUGTRAQ">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
      <ref url="http://securityreason.com/securityalert/4004" source="SREASON">4004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1562" published="2003-12-31" name="CVE-2003-1562" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7482" source="BID">7482</ref>
      <ref url="http://www.securityfocus.com/archive/1/320440" source="BUGTRAQ">20030505 Re: OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://www.securityfocus.com/archive/1/320302" source="BUGTRAQ">20030501 Re: OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://www.securityfocus.com/archive/1/320153" source="BUGTRAQ">20030501 Re: OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=248747" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=248747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.27" />
        <vers num="1.2.3" />
        <vers num="1.3" />
        <vers num="1.5" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.9" />
        <vers num="2.9.9" />
        <vers num="2.9.9p2" />
        <vers num="2.9p1" />
        <vers num="2.9p2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1p1" />
        <vers num="3.0.2" />
        <vers num="3.0.2p1" />
        <vers num="3.0p1" />
        <vers num="3.1" />
        <vers num="3.1p1" />
        <vers num="3.2" />
        <vers num="3.2.2" />
        <vers num="3.2.2p1" />
        <vers num="3.2.3p1" />
        <vers num="3.3" />
        <vers num="3.3p1" />
        <vers num="3.4" />
        <vers num="3.4p1" />
        <vers num="3.5" />
        <vers num="3.5p1" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.1p1" />
        <vers num="3.6.1p2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1563" published="2003-12-31" name="CVE-2003-1563" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.auscert.org.au/render.html?it=3672" source="AUSCERT">ESB-2003.0843</ref>
      <ref url="http://www.securityfocus.com/bid/9137" source="BID">9137</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3672" source="SUNALERT">57428</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-200810-1" source="SUNALERT">200810</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101393-1" source="SUNALERT">101393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cluster">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":sparc" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1564" published="2003-12-31" name="CVE-2003-1564" modified="2008-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xmlsoft.org/news.html" source="MISC">http://xmlsoft.org/news.html</ref>
      <ref url="http://www.stylusstudio.com/xmldev/200302/post20020.html" source="MLIST">[xml-dev] 20030202 Re: Elliotte Rusty Harold on Web Services</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0886.html" source="REDHAT">RHSA-2008:0886</ref>
      <ref url="http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2" source="MISC">http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2</ref>
      <ref url="http://secunia.com/advisories/31868" source="SECUNIA">31868</ref>
      <ref url="http://mail.gnome.org/archives/xml/2008-August/msg00034.html" source="MLIST">[xml] 20080820 Security fix for libxml2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmlsoft" name="libxml2">
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.13" />
        <vers num="1.8.14" />
        <vers num="1.8.16" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.9" />
        <vers num="2.0.0" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" edition="beta" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.11" />
        <vers num="2.3.12" />
        <vers num="2.3.13" />
        <vers num="2.3.14" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" />
        <vers num="2.4.28" />
        <vers num="2.4.29" />
        <vers num="2.4.3" />
        <vers num="2.4.30" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-1565" reject="1" published="2003-08-27" name="CVE-2003-1565" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2002-1565.  Reason: This candidate is a duplicate of CVE-2002-1565.  Notes: All CVE users should reference CVE-2002-1565 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1566" published="2009-01-14" name="CVE-2003-1566" modified="2009-12-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14077" source="XF">iis-improper-httptrack-logging(14077)</ref>
      <ref url="http://www.securityfocus.com/bid/9313" source="BID">9313</ref>
      <ref url="http://www.osvdb.org/4864" source="OSVDB">4864</ref>
      <ref url="http://www.aqtronix.com/Advisories/AQ-2003-02.txt" source="MISC">http://www.aqtronix.com/Advisories/AQ-2003-02.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html" source="NTBUGTRAQ">20031227 AQ-2003-02: Microsoft IIS Logging Failure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_services">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1567" published="2009-01-14" name="CVE-2003-1567" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/288308" source="CERT-VN">VU#288308</ref>
      <ref url="http://www.osvdb.org/5648" source="OSVDB">5648</ref>
      <ref url="http://www.aqtronix.com/Advisories/AQ-2003-02.txt" source="MISC">http://www.aqtronix.com/Advisories/AQ-2003-02.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html" source="NTBUGTRAQ">20031227 AQ-2003-02: Microsoft IIS Logging Failure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_services">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1568" published="2009-02-06" name="CVE-2003-1568" modified="2009-02-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://data.goahead.com/Software/Webserver/2.1.8/release.htm#null-pointer-crash-in-webssafeurl" source="CONFIRM">http://data.goahead.com/Software/Webserver/2.1.8/release.htm#null-pointer-crash-in-webssafeurl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goahead" name="goahead_webserver">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
      </prod>
      <prod vendor="goahead_software" name="goahead_webserver">
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers prev="1" num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1569" published="2009-02-06" name="CVE-2003-1569" modified="2009-02-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-aux-denial-of-service" source="CONFIRM">http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-aux-denial-of-service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goahead" name="goahead_webserver">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers prev="1" num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1570" published="2009-03-31" name="CVE-2003-1570" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49536" source="XF">tsm-consolemode-info-disclosure(49536)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0881" source="VUPEN" adv="1">ADV-2009-0881</ref>
      <ref url="http://www.securityfocus.com/bid/34285" source="BID">34285</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC37554" source="AIXAPAR" adv="1">IC37554</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21375360" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21375360</ref>
      <ref url="http://securitytracker.com/id?1021947" source="SECTRACK">1021947</ref>
      <ref url="http://secunia.com/advisories/34498" source="SECUNIA" adv="1">34498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager">
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1571" published="2009-04-02" name="CVE-2003-1571" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb.  NOTE: it was later reported that 8.21 is also affected.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/2492" source="OSVDB">2492</ref>
      <ref url="http://www.milw0rm.com/exploits/7488" source="MILW0RM">7488</ref>
      <ref url="http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=25863" source="MISC">http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=25863</ref>
      <ref url="http://secunia.com/advisories/9639" source="SECUNIA" adv="1">9639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwizguide" name="web_wiz_guestbook">
        <vers num="6.0" />
        <vers num="8.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1572" published="2009-06-01" name="CVE-2003-1572" modified="2009-06-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.illegalaccess.org/java/jmf.php" source="MISC">http://www.illegalaccess.org/java/jmf.php</ref>
      <ref url="http://securitytracker.com/id?1006777" source="SECTRACK">1006777</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2003/06/msg00219.html" source="BUGTRAQ">20030625 Privilege escalation applet, Java Media Framework</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jmf">
        <vers num="2.1.1" />
        <vers num="2.1.1a" />
        <vers num="2.1.1b" />
        <vers num="2.1.1c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1573" published="2009-06-01" name="CVE-2003-1573" modified="2009-06-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14008" source="XF" patch="1">j2ee-pointbase-sql-injection(14008)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14883" source="XF">pointbase-command-execution(14883)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14882" source="XF">pointbase-information-disclosure(14882)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14881" source="XF">pointbase-insecure-permissions-dos(14881)</ref>
      <ref url="http://www.securityfocus.com/bid/9230" source="BID">9230</ref>
      <ref url="http://securitytracker.com/id?1008491" source="SECTRACK">1008491</ref>
      <ref url="http://secunia.com/advisories/10460" source="SECUNIA" adv="1">10460</ref>
      <ref url="http://seclists.org/bugtraq/2003/Dec/0249.html" source="BUGTRAQ">20031216 J2EE 1.4 reference implementation: database component allows remote code execution</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0675.html" source="FULLDISC">20040118 Proof-Of-Concept Denial-Of-Service Pointbase 4.6 Java SQL-DB</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0148.html" source="BUGTRAQ">20040118 Proof-Of-Concept Denial-Of-Service Pointbase 4.6 Java SQL-DB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="j2ee">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1574" published="2009-08-24" name="CVE-2003-1574" modified="2009-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/14170" source="BID" patch="1">14170</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=748739&amp;group_id=64258&amp;atid=506846" source="CONFIRM" patch="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=748739&amp;group_id=64258&amp;atid=506846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40347" source="XF">tikiwiki-username-security-byass(40347)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki" name="tikiwiki">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1575" published="2010-01-28" name="CVE-2003-1575" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200161-1" source="SUNALERT" patch="1" adv="1">200161</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113207-05-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113207-05-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="vxfs">
        <vers num="3.3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1576" published="2010-01-28" name="CVE-2003-1576" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in pamverifier in Change Manager (CM) 1.0 for Sun Management Center (SunMC) 3.0 on Solaris 8 and 9 on the sparc platform allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-201231-1



    * "SunMC Change Manager" 1.0 is an unbundled Sun Management Center (SunMC) 3.0 add-on. It is not a part of the SunMC "base" product.
    * Solaris 2.6 and 7 are not affected. Solaris on the x86 platform is not affected.
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201231-1" source="SUNALERT" patch="1" adv="1">201231</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113105-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113105-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="change_manager">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1577" published="2010-02-05" name="CVE-2003-1577" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a crafted DNS response, related to an "Inverse Lookup Log Corruption (ILLC)" issue, a different vulnerability than CVE-2002-1315 and CVE-2002-1316.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201453-1" source="SUNALERT" patch="1" adv="1">201453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56632" source="XF">sunone-iplanetlog-xss(56632)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers prev="1" num="4.1" edition="sp1" />
        <vers prev="1" num="4.1" edition="sp10" />
        <vers prev="1" num="4.1" edition="sp11" />
        <vers prev="1" num="4.1" edition="sp12" />
        <vers prev="1" num="4.1" edition="sp2" />
        <vers prev="1" num="4.1" edition="sp3" />
        <vers prev="1" num="4.1" edition="sp4" />
        <vers prev="1" num="4.1" edition="sp5" />
        <vers prev="1" num="4.1" edition="sp6" />
        <vers prev="1" num="4.1" edition="sp7" />
        <vers prev="1" num="4.1" edition="sp8" />
        <vers prev="1" num="4.1" edition="sp9" />
        <vers prev="1" num="6.0" edition="sp1" />
        <vers prev="1" num="6.0" edition="sp2" />
        <vers prev="1" num="6.0" edition="sp3" />
        <vers prev="1" num="6.0" edition="sp4" />
        <vers prev="1" num="6.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1578" published="2010-02-05" name="CVE-2003-1578" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7012" source="BID" patch="1">7012</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201453-1" source="SUNALERT" patch="1" adv="1">201453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56633" source="XF">iplanet-logpreview-security-bypass(56633)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers prev="1" num="4.1" edition="sp1" />
        <vers prev="1" num="4.1" edition="sp10" />
        <vers prev="1" num="4.1" edition="sp11" />
        <vers prev="1" num="4.1" edition="sp12" />
        <vers prev="1" num="4.1" edition="sp2" />
        <vers prev="1" num="4.1" edition="sp3" />
        <vers prev="1" num="4.1" edition="sp4" />
        <vers prev="1" num="4.1" edition="sp5" />
        <vers prev="1" num="4.1" edition="sp6" />
        <vers prev="1" num="4.1" edition="sp7" />
        <vers prev="1" num="4.1" edition="sp8" />
        <vers prev="1" num="4.1" edition="sp9" />
        <vers prev="1" num="6.0" edition="sp1" />
        <vers prev="1" num="6.0" edition="sp2" />
        <vers prev="1" num="6.0" edition="sp3" />
        <vers prev="1" num="6.0" edition="sp4" />
        <vers prev="1" num="6.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1579" published="2010-02-05" name="CVE-2003-1579" modified="2010-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1580" published="2010-02-05" name="CVE-2003-1580" modified="2010-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1581" published="2010-02-05" name="CVE-2003-1581" modified="2010-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1582" published="2010-02-05" name="CVE-2003-1582" modified="2010-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="iis">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1583" published="2010-02-05" name="CVE-2003-1583" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56650" source="XF">webtrends-domain-name-xss(56650)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtrends" name="webtrends_log_analyzer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1584" published="2010-02-05" name="CVE-2003-1584" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56649" source="XF">surfstats-domain-name-xss(56649)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="surfstats" name="surfstats">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1585" published="2010-02-05" name="CVE-2003-1585" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56647" source="XF">weblogexpert-domain-name-xss(56647)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alentum" name="weblog_expert">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1586" published="2010-02-05" name="CVE-2003-1586" modified="2010-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56646" source="XF">webexpert-useragent-xss(56646)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="webexpert">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1587" published="2010-02-05" name="CVE-2003-1587" modified="2010-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56645" source="XF">loganpro-useragent-xss(56645)</ref>
      <ref url="http://www.securityfocus.com/archive/1/313867" source="BUGTRAQ">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="loganpro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-1588" published="2010-02-08" name="CVE-2003-1588" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56617" source="XF">suncluster-haoracle-information-disclosure(56617)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201460-1" source="SUNALERT" adv="1">201460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cluster">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1589" published="2010-02-25" name="CVE-2003-1589" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201454-1" source="SUNALERT" patch="1" adv="1">201454</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56616" source="XF">iplanet-unspecified-dos(56616)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp10" />
        <vers num="4.1" edition="sp11" />
        <vers num="4.1" edition="sp12" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
        <vers num="4.1" edition="sp5" />
        <vers num="4.1" edition="sp6" />
        <vers num="4.1" edition="sp7" />
        <vers num="4.1" edition="sp8" />
        <vers num="4.1" edition="sp9" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1590" published="2010-02-25" name="CVE-2003-1590" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201451-1" source="SUNALERT" patch="1" adv="1">201451</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56615" source="XF">sunone-unspecified-dos(56615)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_web_server">
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1591" published="2010-04-05" name="CVE-2003-1591" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allows user-assisted remote attackers to cause a denial of service (console hang) via a large number of FTP sessions, which are not properly handled during an NLM unload.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-1592" published="2010-04-05" name="CVE-2003-1592" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1593" published="2010-04-05" name="CVE-2003-1593" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1594" published="2010-04-05" name="CVE-2003-1594" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1595" published="2010-04-05" name="CVE-2003-1595" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-1596" published="2010-04-05" name="CVE-2003-1596" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers num="5.01i" />
        <vers num="5.01o" />
        <vers num="5.01w" />
        <vers num="5.01y" />
        <vers num="5.02b" />
        <vers num="5.02i" />
        <vers num="5.02r" />
        <vers num="5.02y" />
        <vers prev="1" num="5.03b" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
</nvd>
