<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-05-23" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2003-0001" published="2003-01-17" name="CVE-2003-0001" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/412115" source="CERT-VN" adv="1">VU#412115</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-025.html" source="REDHAT">RHSA-2003:025</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf" source="MISC">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a010603-1.txt" source="ATSTAKE" adv="1">A010603-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104222046632243&amp;w=2" source="BUGTRAQ" adv="1">20030110 More information regarding Etherleak</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html" source="VULNWATCH">20030110 More information regarding Etherleak</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded" source="BUGTRAQ">20030117 Re: More information regarding Etherleak</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded" source="BUGTRAQ">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-088.html" source="REDHAT">RHSA-2003:088</ref>
      <ref url="http://www.osvdb.org/9962" source="OSVDB">9962</ref>
      <ref url="http://secunia.com/advisories/7996" source="SECUNIA">7996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665" source="OVAL" sig="1">oval:org.mitre.oval:def:2665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0002" published="2003-02-07" name="CVE-2003-0002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-002.asp" source="MS" patch="1" adv="1">MS03-002</ref>
      <ref url="http://www.iss.net/security_center/static/10318.php" source="XF" patch="1" adv="1">mcms-manuallogin-reasontxt-xss (10318)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103417794800719&amp;w=2" source="BUGTRAQ" adv="1">20021007 CSS on Microsoft Content Management Server</ref>
      <ref url="http://www.securityfocus.com/bid/5922" source="BID">5922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="content_management_server">
        <vers num="2001" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0003" published="2003-02-07" name="CVE-2003-0003" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/610986" source="CERT-VN" patch="1" adv="1">VU#610986</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-03.html" source="CERT" patch="1" adv="1">CA-2003-03</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-001.asp" source="MS" patch="1" adv="1">MS03-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11132" source="XF" adv="1">win-locator-bo(11132)</ref>
      <ref url="http://www.securityfocus.com/bid/6666" source="BID">6666</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104393588232166&amp;w=2" source="NTBUGTRAQ">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394414713415&amp;w=2" source="BUGTRAQ">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:103" source="OVAL" sig="1">oval:org.mitre.oval:def:103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":server:jp"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0004" published="2003-02-19" name="CVE-2003-0004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-005.asp" source="MS" patch="1" adv="1">MS03-005</ref>
      <ref url="http://www.securityfocus.com/bid/6778" source="BID">6778</ref>
      <ref url="http://www.iss.net/security_center/static/11260.php" source="XF">winxp-windows-redirector-bo(11260)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878038418534&amp;w=2" source="BUGTRAQ">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html" source="VULNWATCH">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0007" published="2003-02-07" name="CVE-2003-0007" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-003.asp" source="MS" patch="1" adv="1">MS03-003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11133" source="XF">outlook-v1-certificate-plaintext(11133)</ref>
      <ref url="http://www.securityfocus.com/bid/6667" source="BID">6667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0009" published="2003-03-07" name="CVE-2003-0009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/489721" source="CERT-VN">VU#489721</ref>
      <ref url="http://www.securityfocus.com/bid/6966" source="BID" patch="1" adv="1">6966</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-006.asp" source="MS" patch="1" adv="1">MS03-006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636383018686&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</ref>
      <ref url="http://www.iss.net/security_center/static/11425.php" source="XF" adv="1">winme-hsc-hcp-bo(11425)</ref>
      <ref url="http://www.osvdb.org/6074" source="OSVDB">6074</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-047.shtml" source="CIAC">N-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0010" published="2003-03-24" name="CVE-2003-0010" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7146" source="BID" patch="1" adv="1">7146</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-008.asp" source="MS" patch="1" adv="1">MS03-008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104812108307645&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html" source="VULNWATCH">20030319 Windows Scripting Engine issue</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26" source="IDEFENSE">20030319 Heap Overflow in Windows Script Engine</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:795" source="OVAL" sig="1">oval:org.mitre.oval:def:795</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:794" source="OVAL" sig="1">oval:org.mitre.oval:def:794</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:200" source="OVAL" sig="1">oval:org.mitre.oval:def:200</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:134" source="OVAL" sig="1">oval:org.mitre.oval:def:134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0011" published="2003-03-24" name="CVE-2003-0011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7145" source="BID" patch="1" adv="1">7145</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-009.asp" source="MS" patch="1" adv="1">MS03-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0012" published="2003-01-17" name="CVE-2003-0012" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
      <ref url="http://www.iss.net/security_center/static/10971.php" source="XF" adv="1">bugzilla-mining-world-writable(10971)</ref>
      <ref url="http://www.securityfocus.com/bid/6502" source="BID">6502</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-012.html" source="REDHAT">RHSA-2003:012</ref>
      <ref url="http://www.debian.org/security/2003/dsa-230" source="DEBIAN">DSA-230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0013" published="2003-01-17" name="CVE-2003-0013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-230" source="DEBIAN" patch="1" adv="1">DSA-230</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/6501" source="BID">6501</ref>
      <ref url="http://www.osvdb.org/6351" source="OSVDB">6351</ref>
      <ref url="http://www.iss.net/security_center/static/10970.php" source="XF">bugzilla-htaccess-database-password(10970)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0014" published="2003-01-11" name="CVE-2003-0014" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <sols>
      <sol source="nvd">For the stable distribution this problem has been fixed in version 1.2-14.2. For the unstable distribution this problem has been fixed in version 1.2-17.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18823" source="XF" patch="1" adv="1">bmv-symlink(18823)</ref>
      <ref url="http://securityfocus.org/bid/12229" source="BID" patch="1" adv="1">12229</ref>
      <ref url="http://www.debian.org/security/2005/dsa-633" source="DEBIAN" adv="1">DSA-633</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog" source="CONFIRM" adv="1">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</ref>
      <ref url="http://securitytracker.com/id?1012847" source="SECTRACK">1012847</ref>
      <ref url="http://secunia.com/advisories/13796" source="SECUNIA">13796</ref>
      <ref url="http://secunia.com/advisories/13793" source="SECUNIA">13793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmv" name="bmv">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0015" published="2003-02-07" name="CVE-2003-0015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/650937" source="CERT-VN" adv="1">VU#650937</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-02.html" source="CERT">CA-2003-02</ref>
      <ref url="http://security.e-matters.de/advisories/012003.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012003.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-013.html" source="REDHAT" patch="1" adv="1">RHSA-2003:013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11108" source="XF" adv="1">cvs-doublefree-memory-corruption(11108)</ref>
      <ref url="http://www.securityfocus.com/bid/6650" source="BID">6650</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-012.html" source="REDHAT">RHSA-2003:012</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009" source="MANDRAKE">MDKSA-2003:009</ref>
      <ref url="http://www.debian.org/security/2003/dsa-233" source="DEBIAN">DSA-233</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-032.shtml" source="CIAC">N-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104438807203491&amp;w=2" source="FREEBSD">FreeBSD-SA-03:01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428571204468&amp;w=2" source="BUGTRAQ">20030202 Exploit for CVS double free() for Linux pserver</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342550612736&amp;w=2" source="BUGTRAQ">20030124 Test program for CVS double-free.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104333092200589&amp;w=2" source="BUGTRAQ">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</ref>
      <ref url="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14" source="CONFIRM">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html" source="VULNWATCH">20030120 Advisory 01/2003: CVS remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.1p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0016" published="2003-02-07" name="CVE-2003-0016" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/979793" source="CERT-VN">VU#979793</ref>
      <ref url="http://www.kb.cert.org/vuls/id/825177" source="CERT-VN">VU#825177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" source="MLIST" patch="1">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</ref>
      <ref url="http://www.apacheweek.com/issues/03-01-24#security" source="CONFIRM">http://www.apacheweek.com/issues/03-01-24#security</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11125" source="XF">apache-device-code-execution(11125)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11124" source="XF">apache-device-name-dos(11124)</ref>
      <ref url="http://www.securityfocus.com/bid/6659" source="BID">6659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0017" published="2003-02-07" name="CVE-2003-0017" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2" source="CONFIRM" patch="1">http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0018" published="2003-02-19" name="CVE-2003-0018" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-025.html" source="REDHAT" patch="1" adv="1">RHSA-2003:025</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.iss.net/security_center/static/11249.php" source="XF" adv="1">linux-odirect-information-leak(11249)</ref>
      <ref url="http://www.securityfocus.com/bid/6763" source="BID">6763</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014" source="MANDRAKE">MDKSA-2003:014</ref>
      <ref url="http://www.debian.org/security/2003/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0019" published="2003-02-19" name="CVE-2003-0019" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/134025" source="CERT-VN">VU#134025</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-056.html" source="REDHAT" patch="1" adv="1">RHSA-2003:056</ref>
      <ref url="http://www.iss.net/security_center/static/11276.php" source="XF" patch="1" adv="1">linux-umlnet-gain-privileges(11276)</ref>
      <ref url="http://www.securityfocus.com/bid/6801" source="BID">6801</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-044.shtml" source="CIAC">N-044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0020" published="2003-03-18" name="CVE-2003-0020" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9930" source="BID" patch="1" adv="1">9930</ref>
      <ref url="http://www.iss.net/security_center/static/11412.php" source="XF" adv="1">apache-esc-seq-injection(11412)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.trustix.org/errata/2004/0027" source="TRUSTIX">2004-0027</ref>
      <ref url="http://www.trustix.org/errata/2004/0017" source="TRUSTIX">2004-0017</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" source="SLACKWARE">SSA:2004-133</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-244.html" source="REDHAT">RHSA-2003:244</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-243.html" source="REDHAT">RHSA-2003:243</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-139.html" source="REDHAT">RHSA-2003:139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-104.html" source="REDHAT">RHSA-2003:104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-083.html" source="REDHAT">RHSA-2003:083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-082.html" source="REDHAT">RHSA-2003:082</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050" source="MANDRAKE">MDKSA-2003:050</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-22.xml" source="GENTOO">GLSA-200405-22</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" source="BUGTRAQ">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE">APPLE-SA-2004-05-03</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046" source="MANDRAKE">MDKSA-2004:046</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4114" source="OVAL" sig="1">oval:org.mitre.oval:def:4114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:150" source="OVAL" sig="1">oval:org.mitre.oval:def:150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100109" source="OVAL" sig="1">oval:org.mitre.oval:def:100109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0021" published="2003-03-03" name="CVE-2003-0021" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11413.php" source="XF" adv="1">terminal-emulator-screen-dump(11413)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6936" source="BID">6936</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" source="MANDRAKE">MDKSA-2003:040</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.8.10"/>
        <vers num="0.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0022" published="2003-03-03" name="CVE-2003-0022" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11413.php" source="XF" adv="1">terminal-emulator-screen-dump(11413)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6938" source="BID">6938</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-055.html" source="REDHAT">RHSA-2003:055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-054.html" source="REDHAT">RHSA-2003:054</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" source="MANDRAKE">MDKSA-2003:034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0023" published="2003-03-03" name="CVE-2003-0023" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11416.php" source="XF" adv="1">terminal-emulator-menu-modification(11416)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6947" source="BID">6947</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-055.html" source="REDHAT">RHSA-2003:055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-054.html" source="REDHAT">RHSA-2003:054</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034" source="MANDRAKE">MDKSA-2003:034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0024" published="2003-03-03" name="CVE-2003-0024" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11416.php" source="XF" adv="1">terminal-emulator-menu-modification(11416)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6949" source="BID">6949</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aterm" name="aterm">
        <vers num="0.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0025" published="2003-01-17" name="CVE-2003-0025" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-229" source="DEBIAN" patch="1" adv="1">DSA-229</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104204786206563&amp;w=2" source="BUGTRAQ" adv="1">20030108 IMP 2.x SQL injection vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/id?1005904" source="SECTRACK">1005904</ref>
      <ref url="http://www.securityfocus.com/bid/6559" source="BID">6559</ref>
      <ref url="http://www.securityfocus.com/archive/1/306268" source="BUGTRAQ">20030108 Re: IMP 2.x SQL injection vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/8177" source="SECUNIA">8177</ref>
      <ref url="http://secunia.com/advisories/8087" source="SECUNIA">8087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0026" published="2003-01-17" name="CVE-2003-0026" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/284857" source="CERT-VN" patch="1" adv="1">VU#284857</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-01.html" source="CERT" patch="1" adv="1">CA-2003-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-011.html" source="REDHAT" patch="1" adv="1">RHSA-2003:011</ref>
      <ref url="http://www.debian.org/security/2003/dsa-231" source="DEBIAN" patch="1" adv="1">DSA-231</ref>
      <ref url="http://www.suse.com/de/security/2003_006_dhcp.html" source="SUSE">SuSE-SA:2003:0006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11073" source="XF">dhcpd-minires-multiple-bo(11073)</ref>
      <ref url="http://www.suse.com/de/security/2003_006_dhcp.html" source="SUSE">SuSE-SA:2003:0006</ref>
      <ref url="http://www.securitytracker.com/id?1005924" source="SECTRACK">1005924</ref>
      <ref url="http://www.securityfocus.com/bid/6627" source="BID">6627</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html" source="OPENPKG">OpenPKG-SA-2003.002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007" source="MANDRAKE">MDKSA-2003:007</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-031.shtml" source="CIAC">N-031</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562" source="CONECTIVA">CLA-2003:562</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html" source="BUGTRAQ">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0"/>
        <vers num="3.0.1" edition="rc1"/>
        <vers num="3.0.1" edition="rc2"/>
        <vers num="3.0.1" edition="rc3"/>
        <vers num="3.0.1" edition="rc4"/>
        <vers num="3.0.1" edition="rc5"/>
        <vers num="3.0.1" edition="rc6"/>
        <vers num="3.0.1" edition="rc7"/>
        <vers num="3.0.1" edition="rc8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0027" published="2003-02-07" name="CVE-2003-0027" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/850785" source="CERT-VN" patch="1" adv="1">VU#850785</ref>
      <ref url="http://www.entercept.com/news/uspr/01-22-03.asp" source="MISC" patch="1" adv="1">http://www.entercept.com/news/uspr/01-22-03.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11129" source="XF">solaris-kcms-directory-traversal(11129)</ref>
      <ref url="http://www.securityfocus.com/bid/6665" source="BID">6665</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104" source="SUNALERT">50104</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104326556329850&amp;w=2" source="BUGTRAQ">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2592" source="OVAL" sig="1">oval:org.mitre.oval:def:2592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:195" source="OVAL" sig="1">oval:org.mitre.oval:def:195</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:120" source="OVAL" sig="1">oval:org.mitre.oval:def:120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition=""/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":x86"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0028" published="2003-03-25" name="CVE-2003-0028" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-10.html" source="CERT" patch="1" adv="1">CA-2003-10</ref>
      <ref url="http://www.kb.cert.org/vuls/id/516825" source="CERT-VN">VU#516825</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-089.html" source="REDHAT">RHSA-2003:089</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_027_glibc.html" source="SUSE">SuSE-SA:2003:027</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html" source="ENGARDE">ESA-20030321-010</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20030318.html" source="EEYE" adv="1">AD20030318</ref>
      <ref url="http://www.debian.org/security/2003/dsa-282" source="DEBIAN">DSA-282</ref>
      <ref url="http://www.debian.org/security/2003/dsa-272" source="DEBIAN">DSA-272</ref>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN">DSA-266</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878237121402&amp;w=2" source="TRUSTIX">2003-0014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104860855114117&amp;w=2" source="BUGTRAQ">20030325 GLSA:  glibc (200303-22)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811415301340&amp;w=2" source="BUGTRAQ">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104810574423662&amp;w=2" source="BUGTRAQ">20030319 EEYE: XDR Integer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html" source="VULNWATCH">20030319 EEYE: XDR Integer Overflow</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc" source="NETBSD">NetBSD-SA2003-008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316931/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: dietlibc (200303-29)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/315638/30/25430/threaded" source="BUGTRAQ">20030319 RE: EEYE: XDR Integer Overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037" source="MANDRAKE">MDKSA-2003:037</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:230" source="OVAL" sig="1">oval:org.mitre.oval:def:230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
      </prod>
      <prod vendor="openafs" name="openafs">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.4a"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.1a"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.2a"/>
        <vers num="1.2.2b"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
      </prod>
      <prod vendor="cray" name="unicos">
        <vers num="6.0"/>
        <vers num="6.0e"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="8.3"/>
        <vers num="9.0"/>
        <vers num="9.0.2.5"/>
        <vers num="9.2"/>
        <vers num="9.2.4"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="stable"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod vendor="hp" name="hp-ux_series_700">
        <vers num="10.20"/>
      </prod>
      <prod vendor="hp" name="hp-ux_series_800">
        <vers num="10.20"/>
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition=""/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":x86"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0030" published="2003-03-18" name="CVE-2003-0030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/247545" source="CERT-VN" patch="1" adv="1">VU#247545</ref>
      <ref url="http://www.securityfocus.com/bid/7085" source="BID" adv="1">7085</ref>
      <ref url="http://www.securityfocus.com/bid/7084" source="BID" adv="1">7084</ref>
      <ref url="http://www.securityfocus.com/bid/7083" source="BID" adv="1">7083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104758650516677&amp;w=2" source="BUGTRAQ" adv="1">20030313 Protegrity buffer overflow</ref>
      <ref url="http://secunia.com/advisories/8294" source="SECUNIA">8294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="protegrity" name="secure.data">
        <vers num="2.2.3.7"/>
        <vers num="2.2.3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0031" published="2003-01-17" name="CVE-2003-0031" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-228" source="DEBIAN" patch="1" adv="1">DSA-228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030103 Multiple libmcrypt vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/id?1006181" source="SECTRACK">1006181</ref>
      <ref url="http://www.securityfocus.com/bid/6510" source="BID">6510</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2" source="BUGTRAQ">20030105 GLSA:  libmcrypt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" source="CONECTIVA">CLA-2003:567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcrypt" name="libmcrypt">
        <vers num="2.5.1_r4"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0032" published="2003-01-17" name="CVE-2003-0032" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-228" source="DEBIAN" patch="1" adv="1">DSA-228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030103 Multiple libmcrypt vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/10988.php" source="XF" adv="1">libmcrypt-libtool-memory-leak(10988)</ref>
      <ref url="http://www.securityfocus.com/bid/6512" source="BID">6512</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2" source="BUGTRAQ">20030105 GLSA:  libmcrypt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567" source="CONECTIVA">CLA-2003:567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcrypt" name="libmcrypt">
        <vers num="2.5.1_r4"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0033" published="2003-03-07" name="CVE-2003-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/916785" source="CERT-VN" adv="1">VU#916785</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-13.html" source="CERT">CA-2003-13</ref>
      <ref url="http://www.securityfocus.com/bid/6963" source="BID" patch="1" adv="1">6963</ref>
      <ref url="http://www.iss.net/security_center/static/10956.php" source="XF" patch="1" adv="1">snort-rpc-fragment-bo(10956)</ref>
      <ref url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951" source="ISS" patch="1" adv="1">20030303 Snort RPC Preprocessing Vulnerability</ref>
      <ref url="http://www.osvdb.org/4418" source="OSVDB">4418</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029" source="MANDRAKE">MDKSA-2003:029</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html" source="ENGARDE">ESA-20030307-007</ref>
      <ref url="http://www.debian.org/security/2003/dsa-297" source="DEBIAN">DSA-297</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2" source="GENTOO">GLSA-200304-06</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716001503409&amp;w=2" source="GENTOO">GLSA-200303-6.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673386226064&amp;w=2" source="BUGTRAQ">20030303 Snort RPC Vulnerability (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snort" name="snort">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0034" published="2003-02-07" name="CVE-2003-0034" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.21.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" source="VULNWATCH">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.securitytracker.com/id?1005959" source="SECTRACK">1005959</ref>
      <ref url="http://www.securityfocus.com/bid/6656" source="BID">6656</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" source="MANDRAKE">MDKSA-2003:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jean-jacques_sarton" name="mtink">
        <vers num="0.9.32"/>
        <vers num="0.9.33"/>
        <vers num="0.9.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0035" published="2003-02-07" name="CVE-2003-0035" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.21.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" source="VULNWATCH">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.securitytracker.com/id?1005959" source="SECTRACK">1005959</ref>
      <ref url="http://www.securityfocus.com/bid/6658" source="BID">6658</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded" source="BUGTRAQ">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" source="MANDRAKE">MDKSA-2003:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robert_krawitz" name="escputil">
        <vers num="1.15.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0036" published="2003-02-07" name="CVE-2003-0036" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.21.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html" source="VULNWATCH">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.securitytracker.com/id?1005959" source="SECTRACK">1005959</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded" source="BUGTRAQ">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010" source="MANDRAKE">MDKSA-2003:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rildo_pragana" name="ml85p">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0037" published="2003-02-07" name="CVE-2003-0037" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-244" source="DEBIAN" patch="1" adv="1">DSA-244</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11181" source="XF">noffle-multiple-bo(11181)</ref>
      <ref url="http://www.securityfocus.com/bid/6695" source="BID">6695</ref>
      <ref url="http://secunia.com/advisories/7955" source="SECUNIA">7955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noffle" name="noffle">
        <vers prev="1" num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0038" published="2003-02-07" name="CVE-2003-0038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-436" source="DEBIAN" patch="1" adv="1">DSA-436</ref>
      <ref url="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt" source="CONFIRM" patch="1">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342745916111" source="BUGTRAQ" adv="1">20030124 Mailman: cross-site scripting bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11152" source="XF">mailman-email-variable-xss(11152)</ref>
      <ref url="http://www.securitytracker.com/id?1005987" source="SECTRACK">1005987</ref>
      <ref url="http://www.securityfocus.com/bid/6677" source="BID">6677</ref>
      <ref url="http://www.osvdb.org/9205" source="OSVDB">9205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0039" published="2003-02-07" name="CVE-2003-0039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/149953" source="CERT-VN">VU#149953</ref>
      <ref url="http://www.debian.org/security/2003/dsa-245" source="DEBIAN" patch="1" adv="1">DSA-245</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104310927813830&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030115 DoS against DHCP infrastructure with isc dhcrelay</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11187" source="XF" adv="1">dhcp-dhcrelay-dos(11187)</ref>
      <ref url="http://www.securityfocus.com/bid/6628" source="BID">6628</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-034.html" source="REDHAT">RHSA-2003:034</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html" source="BUGTRAQ">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616" source="CONECTIVA">CLSA-2003:616</ref>
      <ref url="http://cc.turbolinux.com/security/TLSA-2003-26.txt" source="TURBO">TLSA-2003-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0.1" edition="rc1"/>
        <vers num="3.0.1" edition="rc10"/>
        <vers num="3.0.1" edition="rc2"/>
        <vers num="3.0.1" edition="rc3"/>
        <vers num="3.0.1" edition="rc4"/>
        <vers num="3.0.1" edition="rc5"/>
        <vers num="3.0.1" edition="rc6"/>
        <vers num="3.0.1" edition="rc7"/>
        <vers num="3.0.1" edition="rc8"/>
        <vers num="3.0.1" edition="rc9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0040" published="2003-02-19" name="CVE-2003-0040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6738" source="BID" patch="1" adv="1">6738</ref>
      <ref url="http://www.debian.org/security/2003/dsa-247" source="DEBIAN" patch="1" adv="1">DSA-247</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11213" source="XF">courierimap-authmysqllib-sql-injection(11213)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="double_precision_incorporated" name="courier_mta">
        <vers num="0.37.3"/>
      </prod>
      <prod vendor="inter7" name="courier-imap">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0041" published="2003-02-19" name="CVE-2003-0041" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-020.html" source="REDHAT" patch="1" adv="1">RHSA-2003:020</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html" source="VULNWATCH">20030128 MIT Kerberos FTP client remote shell commands execution</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021" source="MANDRAKE">MDKSA-2003:021</ref>
      <ref url="http://secunia.com/advisories/8114" source="SECUNIA">8114</ref>
      <ref url="http://secunia.com/advisories/7979" source="SECUNIA">7979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos_ftp_client">
        <vers num=""/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":i386"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":i386"/>
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":i386"/>
        <vers num="7.2" edition=""/>
        <vers num="7.2" edition=":i386"/>
        <vers num="7.2" edition=":ia64"/>
        <vers num="7.3" edition=""/>
        <vers num="7.3" edition=":i386"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0042" published="2003-02-07" name="CVE-2003-0042" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-246" source="DEBIAN" patch="1" adv="1">DSA-246</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394568616290&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11194" source="XF">tomcat-null-directory-listing(11194)</ref>
      <ref url="http://www.securityfocus.com/bid/6721" source="BID">6721</ref>
      <ref url="http://www.securityfocus.com/advisories/5111" source="HP">HPSBUX0303-249</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-060.shtml" source="CIAC">N-060</ref>
      <ref url="http://secunia.com/advisories/7977" source="SECUNIA">7977</ref>
      <ref url="http://secunia.com/advisories/7972" source="SECUNIA">7972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0043" published="2003-02-07" name="CVE-2003-0043" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11195" source="XF" adv="1">tomcat-webxml-read-files(11195)</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref url="http://www.securityfocus.com/bid/6722" source="BID">6722</ref>
      <ref url="http://www.securityfocus.com/advisories/5111" source="HP">HPSBUX0303-249</ref>
      <ref url="http://www.debian.org/security/2003/dsa-246" source="DEBIAN">DSA-246</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-060.shtml" source="CIAC">N-060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0044" published="2003-02-07" name="CVE-2003-0044" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-246" source="DEBIAN" patch="1" adv="1">DSA-246</ref>
      <ref url="http://www.securityfocus.com/advisories/5111" source="HP">HPSBUX0303-249</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11196" source="XF">tomcat-web-app-xss(11196)</ref>
      <ref url="http://www.securityfocus.com/bid/6720" source="BID">6720</ref>
      <ref url="http://www.osvdb.org/9204" source="OSVDB">9204</ref>
      <ref url="http://www.osvdb.org/9203" source="OSVDB">9203</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-060.shtml" source="CIAC">N-060</ref>
      <ref url="http://secunia.com/advisories/7972" source="SECUNIA">7972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0045" published="2003-02-07" name="CVE-2003-0045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12102" source="XF" adv="1">jakarta-tomcat-msdos-dos(12102)</ref>
      <ref url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" source="CONFIRM" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0046" published="2003-02-19" name="CVE-2003-0046" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.28.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref url="http://www.celestialsoftware.net/telnet/beta_software.html" source="CONFIRM" adv="1">http://www.celestialsoftware.net/telnet/beta_software.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" source="BUGTRAQ">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref url="http://www.securitytracker.com/id?1006013" source="SECTRACK">1006013</ref>
      <ref url="http://www.securityfocus.com/bid/6725" source="BID">6725</ref>
      <ref url="http://www.osvdb.org/7686" source="OSVDB">7686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="celestial_software" name="absolutetelnet">
        <vers num="2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0047" published="2003-02-19" name="CVE-2003-0047" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.28.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" source="BUGTRAQ">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref url="http://www.securitytracker.com/id?1006012" source="SECTRACK">1006012</ref>
      <ref url="http://www.securitytracker.com/id?1006011" source="SECTRACK">1006011</ref>
      <ref url="http://www.securitytracker.com/id?1006010" source="SECTRACK">1006010</ref>
      <ref url="http://www.securityfocus.com/bid/6728" source="BID">6728</ref>
      <ref url="http://www.securityfocus.com/bid/6727" source="BID">6727</ref>
      <ref url="http://www.securityfocus.com/bid/6726" source="BID">6726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="van_dyke_technologies" name="entunnel">
        <vers prev="1" num="1.0.2"/>
      </prod>
      <prod vendor="van_dyke_technologies" name="securecrt">
        <vers num="3.4.7"/>
        <vers num="4.0.2"/>
      </prod>
      <prod vendor="van_dyke_technologies" name="securefx">
        <vers num="2.0.4"/>
        <vers num="2.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0048" published="2003-02-19" name="CVE-2003-0048" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/01.28.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref url="http://www.securitytracker.com/id?1006014" source="SECTRACK">1006014</ref>
      <ref url="http://www.securityfocus.com/bid/6724" source="BID">6724</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2" source="BUGTRAQ">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers num="0.48"/>
        <vers num="0.49"/>
        <vers num="0.53"/>
        <vers num="0.53b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0049" published="2003-03-03" name="CVE-2003-0049" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.iss.net/security_center/static/11333.php" source="XF" adv="1">macos-afp-unauthorized-access(11333)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6860" source="BID">6860</ref>
      <ref url="http://securitytracker.com/id?1006107" source="SECTRACK">1006107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0050" published="2003-03-07" name="CVE-2003-0050" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11401.php" source="XF" adv="1">quicktime-darwin-command-execution(11401)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6954" source="BID">6954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2"/>
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0051" published="2003-03-07" name="CVE-2003-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11402.php" source="XF" adv="1">quicktime-darwin-path-disclosure(11402)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6956" source="BID">6956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2"/>
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0052" published="2003-03-07" name="CVE-2003-0052" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11403.php" source="XF" adv="1">quicktime-darwin-directory-disclosure(11403)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6955" source="BID">6955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2"/>
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0053" published="2003-03-07" name="CVE-2003-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11404.php" source="XF" adv="1">quicktime-darwin-parsexml-xss(11404)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6958" source="BID">6958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2"/>
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0054" published="2003-03-07" name="CVE-2003-0054" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11405.php" source="XF" adv="1">quicktime-darwin-describe-xss(11405)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6960" source="BID">6960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2"/>
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0055" published="2003-03-07" name="CVE-2003-0055" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref url="http://www.iss.net/security_center/static/11406.php" source="XF" adv="1">quicktime-darwin-mp3-bo(11406)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6957" source="BID">6957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime_darwin_mp3_broadcaster">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0056" published="2003-02-19" name="CVE-2003-0056" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-252" source="DEBIAN" patch="1" adv="1">DSA-252</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428624705363&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030202 GLSA:  slocate</ref>
      <ref url="http://www.usg.org.uk/advisories/2003.001.txt" source="MISC" adv="1">http://www.usg.org.uk/advisories/2003.001.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11369" source="OVAL">oval:org.mitre.oval:def:11369</ref>
      <ref url="http://www.net-security.org/advisory.php?id=2010" source="CONECTIVA">CLA-2003:643</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015" source="MANDRAKE">MDKSA-2003:015</ref>
      <ref url="http://secunia.com/advisories/8749" source="SECUNIA">8749</ref>
      <ref url="http://secunia.com/advisories/8236" source="SECUNIA">8236</ref>
      <ref url="http://secunia.com/advisories/8118/" source="SECUNIA">8118</ref>
      <ref url="http://secunia.com/advisories/8007" source="SECUNIA">8007</ref>
      <ref url="http://secunia.com/advisories/7982" source="SECUNIA">7982</ref>
      <ref url="http://secunia.com/advisories/7947" source="SECUNIA">7947</ref>
      <ref url="http://secunia.com/advisories/10720" source="SECUNIA">10720</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-041.html" source="REDHAT">RHSA-2004:041</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104348607205691&amp;w=2" source="BUGTRAQ">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342864418213&amp;w=2" source="BUGTRAQ">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt" source="CALDERA">CSSA-2003-009.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="2.5"/>
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0057" published="2003-02-19" name="CVE-2003-0057" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104369136703903&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030127 Hypermail buffer overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11158" source="XF">hypermail-long-hostname-bo(11158)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11157" source="XF">hypermail-mail-attachment-bo(11157)</ref>
      <ref url="http://www.securityfocus.com/bid/6690" source="BID">6690</ref>
      <ref url="http://www.securityfocus.com/bid/6689" source="BID">6689</ref>
      <ref url="http://www.debian.org/security/2003/dsa-248" source="DEBIAN">DSA-248</ref>
      <ref url="http://secunia.com/advisories/8030" source="SECUNIA">8030</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html" source="VULNWATCH">20030126 Hypermail buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hypermail" name="hypermail">
        <vers num="2.0b25"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0058" published="2003-02-19" name="CVE-2003-0058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/661243" source="CERT-VN" patch="1" adv="1">VU#661243</ref>
      <ref url="http://www.securityfocus.com/bid/6683" source="BID" patch="1" adv="1">6683</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/10099" source="XF">kerberos-kdc-null-pointer-dos(10099)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-168.html" source="REDHAT">RHSA-2003:168</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" source="MANDRAKE">MDKSA-2003:043</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142" source="SUNALERT">50142</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" source="CONECTIVA">CLSA-2003:639</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1110" source="OVAL" sig="1">oval:org.mitre.oval:def:1110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
      </prod>
      <prod vendor="sun" name="enterprise_authentication_mechanism">
        <vers num="1.0"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0059" published="2003-02-19" name="CVE-2003-0059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/684563" source="CERT-VN" patch="1" adv="1">VU#684563</ref>
      <ref url="http://www.securityfocus.com/bid/6714" source="BID" patch="1" adv="1">6714</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11188" source="XF">kerberos-kdc-user-spoofing(11188)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-168.html" source="REDHAT">RHSA-2003:168</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043" source="MANDRAKE">MDKSA-2003:043</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" source="CONECTIVA">CLSA-2003:639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0060" published="2003-02-19" name="CVE-2003-0060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/787523" source="CERT-VN" patch="1" adv="1">VU#787523</ref>
      <ref url="http://www.securityfocus.com/bid/6712" source="BID" patch="1" adv="1">6712</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11189" source="XF">kerberos-kdc-format-string(11189)</ref>
      <ref url="http://www.osvdb.org/4879" source="OSVDB">4879</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639" source="CONECTIVA">CLSA-2003:639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0061" published="2002-01-11" name="CVE-2003-0061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0062" published="2003-02-19" name="CVE-2003-0062" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/02.10.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/02.10.03.txt</ref>
      <ref url="http://www.securityfocus.com/bid/6803" source="BID">6803</ref>
      <ref url="http://www.iss.net/security_center/static/11282.php" source="XF" adv="1">nod32-pathname-bo(11282)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104490777824360&amp;w=2" source="BUGTRAQ">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0063" published="2003-03-03" name="CVE-2003-0063" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6940" source="BID">6940</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-067.html" source="REDHAT">RHSA-2003:067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-066.html" source="REDHAT">RHSA-2003:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-065.html" source="REDHAT">RHSA-2003:065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-064.html" source="REDHAT">RHSA-2003:064</ref>
      <ref url="http://www.debian.org/security/2003/dsa-380" source="DEBIAN">DSA-380</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0064" published="2003-03-03" name="CVE-2003-0064" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6942" source="BID">6942</ref>
      <ref url="http://www.securityfocus.com/advisories/6236" source="HP">HPSBUX0401-309</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition=""/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":x86"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0065" published="2003-03-03" name="CVE-2003-0065" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6945" source="BID">6945</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_university_of_singapore" name="uxterm">
        <vers num="2.3"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0066" published="2003-03-03" name="CVE-2003-0066" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6953" source="BID">6953</ref>
      <ref url="http://www.securityfocus.com/advisories/5137" source="GENTOO">200303-16</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-055.html" source="REDHAT">RHSA-2003:055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-054.html" source="REDHAT">RHSA-2003:054</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003" source="MANDRAKE">MDKSA-2003:003</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0067" published="2003-03-18" name="CVE-2003-0067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aterm" name="aterm">
        <vers num="0.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0068" published="2003-03-03" name="CVE-2003-0068" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/10237" source="BID">10237</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040" source="MANDRAKE">MDKSA-2003:040</ref>
      <ref url="http://www.debian.org/security/2004/dsa-496" source="DEBIAN">DSA-496</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.8.10"/>
        <vers num="0.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0069" published="2003-03-18" name="CVE-2003-0069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.osvdb.org/8347" source="OSVDB">8347</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers num="0.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0070" published="2003-03-03" name="CVE-2003-0070" modified="2010-08-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/77.html

'CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-053.html" source="REDHAT">RHSA-2003:053</ref>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://seclists.org/lists/bugtraq/2003/Mar/0010.html" source="GENTOO">GLSA-200303-2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnome-terminal">
        <vers num="2.0"/>
        <vers num="2.2"/>
      </prod>
      <prod vendor="nalin_dahyabhai" name="vte">
        <vers num="0.11.21"/>
        <vers num="0.12.2"/>
        <vers num="0.14.2"/>
        <vers num="0.15.0"/>
        <vers num="0.16.14"/>
        <vers num="0.17.4"/>
        <vers num="0.20.5"/>
        <vers num="0.22.5"/>
        <vers num="0.24.3"/>
        <vers num="0.25.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0071" published="2003-03-03" name="CVE-2003-0071" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11415.php" source="XF" adv="1">terminal-emulator-dec-udk(11415)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6950" source="BID">6950</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-067.html" source="REDHAT">RHSA-2003:067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-066.html" source="REDHAT">RHSA-2003:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-065.html" source="REDHAT">RHSA-2003:065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-064.html" source="REDHAT">RHSA-2003:064</ref>
      <ref url="http://www.debian.org/security/2003/dsa-380" source="DEBIAN">DSA-380</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0072" published="2003-04-02" name="CVE-2003-0072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN" patch="1" adv="1">DSA-266</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.securityfocus.com/bid/7184" source="BID">7184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" source="SUNALERT">54042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0"/>
        <vers num="1.2.2.beta1"/>
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
        <vers num="5-1.3" edition="alpha1"/>
        <vers num="5_1.0.6"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0073" published="2003-02-19" name="CVE-2003-0073" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-303" source="DEBIAN" patch="1" adv="1">DSA-303</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385719107879&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://www.mysql.com/doc/en/News-3.23.55.html" source="CONFIRM" adv="1">http://www.mysql.com/doc/en/News-3.23.55.html</ref>
      <ref url="http://www.securityfocus.com/bid/6718" source="BID">6718</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-166.html" source="REDHAT">RHSA-2003:166</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-094.html" source="REDHAT">RHSA-2003:094</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-093.html" source="REDHAT">RHSA-2003:093</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013" source="MANDRAKE">MDKSA-2003:013</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html" source="ENGARDE">ESA-20030220-004</ref>
      <ref url="http://www.iss.net/security_center/static/11199.php" source="XF">mysql-mysqlchangeuser-doublefree-dos(11199)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" source="CONECTIVA">CLA-2003:743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:436" source="OVAL" sig="1">oval:org.mitre.oval:def:436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.31"/>
        <vers num="3.23.36"/>
        <vers num="3.23.41"/>
        <vers num="3.23.47"/>
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0074" published="2003-02-19" name="CVE-2003-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6715" source="BID" patch="1" adv="1">6715</ref>
      <ref url="http://www.iss.net/security_center/static/11193.php" source="XF">plptools-plpnsfd-format-string(11193)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386699725019&amp;w=2" source="BUGTRAQ" adv="1">20030129 Re: Local root vuln in SuSE 8.0 plptools package</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385772908969&amp;w=2" source="BUGTRAQ" adv="1">20030129 Local root vuln in SuSE 8.0 plptools package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plptools" name="plptools">
        <vers num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0075" published="2003-02-19" name="CVE-2003-0075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6745" source="BID" patch="1" adv="1">6745</ref>
      <ref url="http://www.pivx.com/luigi/adv/blade942-adv.txt" source="MISC" patch="1" adv="1">http://www.pivx.com/luigi/adv/blade942-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104446346127432&amp;w=2" source="GENTOO" patch="1">GLSA-200302-04</ref>
      <ref url="http://www.iss.net/security_center/static/11227.php" source="XF" adv="1">bladeenc-myfseek-code-execution(11227)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428700106672&amp;w=2" source="BUGTRAQ">20030202 Bladeenc 0.94.2 code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bladeenc" name="bladeenc">
        <vers num="0.92.7"/>
        <vers num="0.93.10"/>
        <vers num="0.94.0"/>
        <vers num="0.94.1"/>
        <vers num="0.94.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0076" published="2003-02-19" name="CVE-2003-0076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104437720116243&amp;w=2" source="BUGTRAQ" patch="1">20030204 GLSA:  qt-dcgui</ref>
      <ref url="http://www.iss.net/security_center/static/11246.php" source="XF" adv="1">qtdcgui-directory-download-files(11246)</ref>
      <ref url="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html" source="CONFIRM" adv="1">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcgui" name="dcgui">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
      </prod>
      <prod vendor="qt-dcgui" name="qt-dcgui">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0077" published="2003-03-18" name="CVE-2003-0077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11414.php" source="XF" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-071.html" source="REDHAT">RHSA-2003:071</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-070.html" source="REDHAT">RHSA-2003:070</ref>
      <ref url="http://www.osvdb.org/4917" source="OSVDB">4917</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hanterm" name="hanterm-xf">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0078" published="2003-03-03" name="CVE-2003-0078" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openssl.org/news/secadv_20030219.txt" source="CONFIRM" patch="1" adv="1">http://www.openssl.org/news/secadv_20030219.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104568426824439&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</ref>
      <ref url="http://www.iss.net/security_center/static/11369.php" source="XF" adv="1">ssl-cbc-information-leak(11369)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-253" source="DEBIAN" adv="1">DSA-253</ref>
      <ref url="http://www.trustix.org/errata/2003/0005" source="TRUSTIX">2003-0005</ref>
      <ref url="http://www.securityfocus.com/bid/6884" source="BID">6884</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-205.html" source="REDHAT">RHSA-2003:205</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-104.html" source="REDHAT">RHSA-2003:104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-082.html" source="REDHAT">RHSA-2003:082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-063.html" source="REDHAT">RHSA-2003:063</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-062.html" source="REDHAT">RHSA-2003:062</ref>
      <ref url="http://www.osvdb.org/3945" source="OSVDB">3945</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020" source="MANDRAKE">MDKSA-2003:020</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html" source="ENGARDE">ESA-20030220-005</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-051.shtml" source="CIAC">N-051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104577183206905&amp;w=2" source="GENTOO">GLSA-200302-10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567627211904&amp;w=2" source="BUGTRAQ">20030219 OpenSSL 0.9.7a and 0.9.6i released</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570" source="CONECTIVA">CLSA-2003:570</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" source="SGI">20030501-01-I</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc" source="NETBSD">NetBSD-SA2003-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c"/>
        <vers num="0.9.2b"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.5a"/>
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.7" edition="beta1"/>
        <vers num="0.9.7" edition="beta2"/>
        <vers num="0.9.7" edition="beta3"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0079" published="2003-03-03" name="CVE-2003-0079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/11415.php" source="XF" adv="1">terminal-emulator-dec-udk(11415)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" source="VULNWATCH" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref url="http://www.securityfocus.com/bid/6944" source="BID">6944</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-071.html" source="REDHAT">RHSA-2003:071</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-070.html" source="REDHAT">RHSA-2003:070</ref>
      <ref url="http://www.osvdb.org/4918" source="OSVDB">4918</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" source="BUGTRAQ">20030224 Terminal Emulator Security Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hanterm" name="hanterm-xf">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0080" published="2003-03-31" name="CVE-2003-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7128" source="BID" patch="1" adv="1">7128</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-072.html" source="REDHAT" patch="1" adv="1">RHSA-2003:072</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11552" source="XF" adv="1">gnomelokkit-forward-bypass-firewall(11552)</ref>
      <ref url="http://www.osvdb.org/4400" source="OSVDB">4400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnome-lokkit">
        <vers num="0.50_21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0081" published="2003-03-18" name="CVE-2003-0081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7049" source="BID" patch="1" adv="1">7049</ref>
      <ref url="http://www.guninski.com/etherre.html" source="MISC" patch="1" adv="1">http://www.guninski.com/etherre.html</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-258" source="DEBIAN" patch="1" adv="1">DSA-258</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11497" source="XF">ethereal-socks-format-string(11497)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-076.html" source="REDHAT">RHSA-2003:076</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" source="SUSE">SuSE-SA:2003:019</ref>
      <ref url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html" source="GENTOO">GLSA-200303-10</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html" source="FULLDISC">20030308 Ethereal format string bug, yet still ethereal much better than windows</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051" source="MANDRAKE">MDKSA-2003:051</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627" source="CONECTIVA">CLSA-2003:627</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:54" source="OVAL" sig="1">oval:org.mitre.oval:def:54</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.8.18"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0082" published="2003-04-02" name="CVE-2003-0082" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN" patch="1" adv="1">DSA-266</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.securityfocus.com/bid/7185" source="BID">7185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1" source="SUNALERT">54042</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430" source="OVAL" sig="1">oval:org.mitre.oval:def:4430</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536" source="OVAL" sig="1">oval:org.mitre.oval:def:2536</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244" source="OVAL" sig="1">oval:org.mitre.oval:def:244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0"/>
        <vers num="1.2.2.beta1"/>
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
        <vers num="5-1.3" edition="alpha1"/>
        <vers num="5_1.0.6"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0083" published="2003-04-02" name="CVE-2003-0083" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-139.html" source="REDHAT" patch="1" adv="1">RHSA-2003:139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
      <ref url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH" source="CONFIRM">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</ref>
      <ref url="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25" source="CONFIRM" adv="1">http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25</ref>
      <ref url="http://secunia.com/advisories/8146" source="SECUNIA">8146</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024081011678&amp;w=2" source="BUGTRAQ">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:151" source="OVAL" sig="1">oval:org.mitre.oval:def:151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0084" published="2003-05-12" name="CVE-2003-0084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7448" source="BID" patch="1" adv="1">7448</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-114.html" source="REDHAT" patch="1" adv="1">RHSA-2003:114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11893" source="XF">modauthany-command-execution(11893)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-113.html" source="REDHAT">RHSA-2003:113</ref>
      <ref url="http://www.itlab.musc.edu/webNIS/mod_auth_any.html" source="CONFIRM">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-090.shtml" source="CIAC">N-090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_auth_any" name="mod_auth_any">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0085" published="2003-03-31" name="CVE-2003-0085" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/298233" source="CERT-VN">VU#298233</ref>
      <ref url="http://www.securityfocus.com/bid/7106" source="BID" patch="1" adv="1">7106</ref>
      <ref url="http://www.debian.org/security/2003/dsa-262" source="DEBIAN" patch="1" adv="1">DSA-262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792723017768&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 Security Bugfix for Samba - Samba 2.2.8 Released</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 GLSA:  samba (200303-11)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-003-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-095.html" source="REDHAT">RHSA-2003:095</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_016_samba.html" source="SUSE">SuSE-SA:2003:016</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" source="SGI">20030302-01-I</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-003-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-096.html" source="REDHAT">RHSA-2003:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" source="MANDRAKE">MDKSA-2003:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" source="GENTOO">GLSA-200303-11</ref>
      <ref url="http://secunia.com/advisories/8303" source="SECUNIA">8303</ref>
      <ref url="http://secunia.com/advisories/8299" source="SECUNIA">8299</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2" source="BUGTRAQ">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:552" source="OVAL" sig="1">oval:org.mitre.oval:def:552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="cifs-9000_server">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
        <vers num="a.01.07"/>
        <vers num="a.01.08"/>
        <vers num="a.01.08.01"/>
        <vers num="a.01.09"/>
        <vers num="a.01.09.01"/>
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0086" published="2003-03-31" name="CVE-2003-0086" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7107" source="BID" patch="1" adv="1">7107</ref>
      <ref url="http://www.debian.org/security/2003/dsa-262" source="DEBIAN" patch="1" adv="1">DSA-262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 GLSA:  samba (200303-11)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-095.html" source="REDHAT">RHSA-2003:095</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_016_samba.html" source="SUSE">SuSE-SA:2003:016</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I" source="SGI">20030302-01-I</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="APPLE">APPLE-SA-2003-03-24</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-096.html" source="REDHAT">RHSA-2003:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032" source="MANDRAKE">MDKSA-2003:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml" source="GENTOO">GLSA-200303-11</ref>
      <ref url="http://secunia.com/advisories/8303" source="SECUNIA">8303</ref>
      <ref url="http://secunia.com/advisories/8299" source="SECUNIA">8299</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2" source="BUGTRAQ">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554" source="OVAL" sig="1">oval:org.mitre.oval:def:554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0087" published="2003-03-03" name="CVE-2003-0087" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/02.12.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/02.12.03.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11309" source="XF">aix-aixterm-libim-bo(11309)</ref>
      <ref url="http://www.securityfocus.com/bid/6840" source="BID">6840</ref>
      <ref url="http://www.osvdb.org/7996" source="OSVDB">7996</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only" source="AIXAPAR">IY40320</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only" source="AIXAPAR">IY40317</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only" source="AIXAPAR">IY40307</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508833214691&amp;w=2" source="BUGTRAQ">20030212 libIM.a buffer overflow vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508375107938&amp;w=2" source="BUGTRAQ">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html" source="VULNWATCH">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_language_support" name="libim">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0088" published="2003-03-03" name="CVE-2003-0088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a021403-1.txt" source="ATSTAKE" patch="1" adv="1">A021403-1</ref>
      <ref url="http://www.iss.net/security_center/static/11332.php" source="XF" adv="1">macos-trublueenvironment-gain-privileges(11332)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt" source="CONFIRM">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://www.securityfocus.com/bid/6859" source="BID">6859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0089" published="2003-12-15" name="CVE-2003-0089" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13623" source="XF" patch="1" adv="1">hp-sd-utilities-bo(13623)</ref>
      <ref url="http://www.securityfocus.com/bid/8986" source="BID" patch="1" adv="1">8986</ref>
      <ref url="http://www.securityfocus.com/advisories/6030" source="HP" patch="1" adv="1">HPSBUX0311-293</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106873965001431&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5466" source="OVAL">oval:org.mitre.oval:def:5466</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0038.html" source="VULNWATCH">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0090" reject="1" published="2003-12-15" name="CVE-2003-0090" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2000-0844.  Reason: This candidate is a duplicate of CVE-2000-0844.  Notes: All CVE users should reference CVE-2000-0844 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0091" published="2003-04-02" name="CVE-2003-0091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html" source="VULNWATCH" patch="1" adv="1">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316957/30/25250/threaded" source="BUGTRAQ">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/8713" source="OSVDB">8713</ref>
      <ref url="http://www.nsfocus.com/english/homepage/sa2003-02.htm" source="MISC">http://www.nsfocus.com/english/homepage/sa2003-02.htm</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-068.shtml" source="CIAC">N-068</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1" source="SUNALERT">52443</ref>
      <ref url="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt" source="MISC">http://packetstormsecurity.org/0304-advisories/sa2003-02.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4383" source="OVAL" sig="1">oval:org.mitre.oval:def:4383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1"/>
        <vers num="2.6"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0092" published="2003-04-02" name="CVE-2003-0092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html" source="VULNWATCH" patch="1" adv="1">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/7240" source="BID">7240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316948/30/25250/threaded" source="BUGTRAQ">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1" source="SUNALERT">52388</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1905" source="OVAL" sig="1">oval:org.mitre.oval:def:1905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1"/>
        <vers num="2.6"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0093" published="2003-03-03" name="CVE-2003-0093" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11324" source="XF">tcpdump-radius-decoder-dos(11324)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-214.html" source="REDHAT">RHSA-2003:214</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-033.html" source="REDHAT">RHSA-2003:033</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-032.html" source="REDHAT">RHSA-2003:032</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" source="MANDRAKE">MDKSA-2003:027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-261" source="DEBIAN">DSA-261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4"/>
        <vers num="3.4a6"/>
        <vers num="3.5"/>
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0094" published="2003-03-03" name="CVE-2003-0094" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11318" source="XF" adv="1">utillinux-mcookie-cookie-predictable(11318)</ref>
      <ref url="http://www.securityfocus.com/bid/6855" source="BID">6855</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016" source="MANDRAKE">MDKSA-2003:016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="util-linux">
        <vers num="2.11n"/>
        <vers num="2.11u"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0095" published="2003-03-03" name="CVE-2003-0095" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/953746" source="CERT-VN">VU#953746</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-05.html" source="CERT" adv="1">CA-2003-05</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/6849" source="BID">6849</ref>
      <ref url="http://www.osvdb.org/6319" source="OSVDB">6319</ref>
      <ref url="http://www.iss.net/security_center/static/11328.php" source="XF" adv="1">oracle-username-bo(11328)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-046.shtml" source="CIAC">N-046</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549693426042&amp;w=2" source="BUGTRAQ" adv="1">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.0.6"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.7"/>
        <vers num="8.1.7.1"/>
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.1.2"/>
        <vers num="9.0.1.3"/>
        <vers num="9.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0096" published="2003-03-03" name="CVE-2003-0096" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/840666" source="CERT-VN" adv="1">VU#840666</ref>
      <ref url="http://www.kb.cert.org/vuls/id/743954" source="CERT-VN">VU#743954</ref>
      <ref url="http://www.kb.cert.org/vuls/id/663786" source="CERT-VN">VU#663786</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-05.html" source="CERT">CA-2003-05</ref>
      <ref url="http://www.securityfocus.com/bid/6850" source="BID">6850</ref>
      <ref url="http://www.securityfocus.com/bid/6848" source="BID">6848</ref>
      <ref url="http://www.securityfocus.com/bid/6847" source="BID">6847</ref>
      <ref url="http://www.nextgenss.com/advisories/ora-tzofstbo.txt" source="MISC">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt" source="MISC">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/ora-bfilebo.txt" source="MISC">http://www.nextgenss.com/advisories/ora-bfilebo.txt</ref>
      <ref url="http://www.iss.net/security_center/static/11327.php" source="XF" adv="1">oracle-totimestamptz-bo(11327)</ref>
      <ref url="http://www.iss.net/security_center/static/11326.php" source="XF">oracle-tzoffset-bo(11326)</ref>
      <ref url="http://www.iss.net/security_center/static/11325.php" source="XF">oracle-bfilename-directory-bo(11325)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-046.shtml" source="CIAC">N-046</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550346303295&amp;w=2" source="BUGTRAQ">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549782327321&amp;w=2" source="BUGTRAQ">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549743326864&amp;w=2" source="BUGTRAQ">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html" source="VULNWATCH">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html" source="VULNWATCH">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html" source="VULNWATCH">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.0.6"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.7"/>
        <vers num="8.1.7.1"/>
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.1.2"/>
        <vers num="9.0.1.3"/>
        <vers num="9.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0097" published="2003-03-03" name="CVE-2003-0097" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567042700840&amp;w=2" source="GENTOO" patch="1" adv="1">GLSA-200302-09</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550977011668&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</ref>
      <ref url="http://www.slackware.com/changelog/current.php?cpu=i386" source="CONFIRM">http://www.slackware.com/changelog/current.php?cpu=i386</ref>
      <ref url="http://www.iss.net/security_center/static/11343.php" source="XF" adv="1">php-cgi-sapi-access(11343)</ref>
      <ref url="http://www.securityfocus.com/bid/6875" source="BID">6875</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567137502557&amp;w=2" source="GENTOO">GLSA-200302-09.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0098" published="2003-03-03" name="CVE-2003-0098" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-277" source="DEBIAN" patch="1" adv="1">DSA-277</ref>
      <ref url="http://www.securityfocus.com/bid/7200" source="BID">7200</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" source="SUSE">SuSE-SA:2003:022</ref>
      <ref url="http://www.iss.net/security_center/static/11334.php" source="XF">apcupsd-logevent-format-string(11334)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137900" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
      <ref url="http://securitytracker.com/id?1006108" source="SECTRACK">1006108</ref>
      <ref url="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt" source="MISC">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</ref>
      <ref url="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6" source="CONFIRM" adv="1">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" source="CALDERA">CSSA-2003-015.0</ref>
      <ref url="http://www.securityfocus.com/bid/6828" source="BID">6828</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" source="MANDRAKE">MDKSA-2003:018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="apcupsd">
        <vers prev="1" num="3.10.4"/>
        <vers prev="1" num="3.8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0099" published="2003-03-03" name="CVE-2003-0099" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-277" source="DEBIAN" patch="1" adv="1">DSA-277</ref>
      <ref url="http://www.securityfocus.com/bid/7200" source="BID">7200</ref>
      <ref url="http://www.iss.net/security_center/static/11491.php" source="XF" adv="1">apcupsd-vsprintf-multiple-bo(11491)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137900" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=137892" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=137892</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html" source="SUSE">SuSE-SA:2003:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" source="MANDRAKE">MDKSA-2003:018</ref>
      <ref url="http://securitytracker.com/id?1006108" source="SECTRACK">1006108</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt" source="CALDERA">CSSA-2003-015.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="apcupsd">
        <vers num="3.8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0100" published="2003-03-03" name="CVE-2003-0100" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104587206702715&amp;w=2" source="BUGTRAQ" patch="1">20030221 Re: Cisco IOS OSPF exploit</ref>
      <ref url="http://www.iss.net/security_center/static/11373.php" source="XF" adv="1">cisco-ios-ospf-bo(11373)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104576100719090&amp;w=2" source="BUGTRAQ">20030220 Cisco IOS OSPF exploit</ref>
      <ref url="http://www.securityfocus.com/bid/6895" source="BID">6895</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.1"/>
        <vers num="11.1(13)"/>
        <vers num="11.1(13)aa"/>
        <vers num="11.1(13)ca"/>
        <vers num="11.1(13)ia"/>
        <vers num="11.1(15)aa"/>
        <vers num="11.1(15)ca"/>
        <vers num="11.1(15)ia"/>
        <vers num="11.1(16)aa"/>
        <vers num="11.1(16)ia"/>
        <vers num="11.1(17)cc"/>
        <vers num="11.1(17)ct"/>
        <vers num="11.1(20)aa4"/>
        <vers num="11.1(24a)"/>
        <vers num="11.1(24b)"/>
        <vers num="11.1(28a)ct"/>
        <vers num="11.1(28a)ia"/>
        <vers num="11.1(36)ca2"/>
        <vers num="11.1(36)cc2"/>
        <vers num="11.1(36)cc4"/>
        <vers num="11.1(7)aa"/>
        <vers num="11.1(7)ca"/>
        <vers num="11.1(9)ia"/>
        <vers num="11.1aa"/>
        <vers num="11.1ca"/>
        <vers num="11.1cc"/>
        <vers num="11.1ct"/>
        <vers num="11.1ia"/>
        <vers num="11.2"/>
        <vers num="11.2(10)bc"/>
        <vers num="11.2(11b)t2"/>
        <vers num="11.2(17)"/>
        <vers num="11.2(19)gs0.2"/>
        <vers num="11.2(19a)gs6"/>
        <vers num="11.2(23a)bc1"/>
        <vers num="11.2(26)p2"/>
        <vers num="11.2(26a)"/>
        <vers num="11.2(26b)"/>
        <vers num="11.2(4)"/>
        <vers num="11.2(4)f"/>
        <vers num="11.2(4)f1"/>
        <vers num="11.2(4)xa"/>
        <vers num="11.2(4)xaf"/>
        <vers num="11.2(8)p"/>
        <vers num="11.2(8)sa1"/>
        <vers num="11.2(8)sa3"/>
        <vers num="11.2(8)sa5"/>
        <vers num="11.2(8.9)sa6"/>
        <vers num="11.2(9)p"/>
        <vers num="11.2(9)xa"/>
        <vers num="11.2bc"/>
        <vers num="11.2f"/>
        <vers num="11.2gs"/>
        <vers num="11.2p"/>
        <vers num="11.2sa"/>
        <vers num="11.2wa3"/>
        <vers num="11.2wa4"/>
        <vers num="11.2xa"/>
        <vers num="11.3"/>
        <vers num="11.3(1)ed"/>
        <vers num="11.3(1)t"/>
        <vers num="11.3(11)b"/>
        <vers num="11.3(11b)"/>
        <vers num="11.3(11b)t2"/>
        <vers num="11.3(11c)"/>
        <vers num="11.3(2)xa"/>
        <vers num="11.3(7)db1"/>
        <vers num="11.3(8)db2"/>
        <vers num="11.3aa"/>
        <vers num="11.3da"/>
        <vers num="11.3db"/>
        <vers num="11.3ha"/>
        <vers num="11.3ma"/>
        <vers num="11.3na"/>
        <vers num="11.3t"/>
        <vers num="11.3wa4"/>
        <vers num="11.3xa"/>
        <vers num="12.0"/>
        <vers num="12.0(1)"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(10)s7"/>
        <vers num="12.0(10)w5"/>
        <vers num="12.0(10)w5(18f)"/>
        <vers num="12.0(10)w5(18g)"/>
        <vers num="12.0(10a)"/>
        <vers num="12.0(11)s6"/>
        <vers num="12.0(11)st4"/>
        <vers num="12.0(11a)"/>
        <vers num="12.0(12)s3"/>
        <vers num="12.0(12a)"/>
        <vers num="12.0(13)s6"/>
        <vers num="12.0(13)w5(19c)"/>
        <vers num="12.0(13)wt6(1)"/>
        <vers num="12.0(13a)"/>
        <vers num="12.0(14)s7"/>
        <vers num="12.0(14)st"/>
        <vers num="12.0(14)st3"/>
        <vers num="12.0(14)w5(20)"/>
        <vers num="12.0(14a)"/>
        <vers num="12.0(15)s3"/>
        <vers num="12.0(15)s6"/>
        <vers num="12.0(15a)"/>
        <vers num="12.0(16)s8"/>
        <vers num="12.0(16)sc3"/>
        <vers num="12.0(16)st1"/>
        <vers num="12.0(16)w5(21)"/>
        <vers num="12.0(16.06)s"/>
        <vers num="12.0(16a)"/>
        <vers num="12.0(17)"/>
        <vers num="12.0(17)s"/>
        <vers num="12.0(17)s4"/>
        <vers num="12.0(17)sl2"/>
        <vers num="12.0(17)sl6"/>
        <vers num="12.0(17)st1"/>
        <vers num="12.0(17)st5"/>
        <vers num="12.0(17a)"/>
        <vers num="12.0(18)s"/>
        <vers num="12.0(18)s5"/>
        <vers num="12.0(18)st1"/>
        <vers num="12.0(18)w5(22b)"/>
        <vers num="12.0(18b)"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xe"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0(2b)"/>
        <vers num="12.0(3)"/>
        <vers num="12.0(3)t2"/>
        <vers num="12.0(3d)"/>
        <vers num="12.0(4)s"/>
        <vers num="12.0(4)t"/>
        <vers num="12.0(4)xe"/>
        <vers num="12.0(4)xe1"/>
        <vers num="12.0(4)xm"/>
        <vers num="12.0(4)xm1"/>
        <vers num="12.0(5)t"/>
        <vers num="12.0(5)t1"/>
        <vers num="12.0(5)wc"/>
        <vers num="12.0(5)wc2"/>
        <vers num="12.0(5)wc2b"/>
        <vers num="12.0(5)wc3"/>
        <vers num="12.0(5)wc3b"/>
        <vers num="12.0(5)wx"/>
        <vers num="12.0(5)xe"/>
        <vers num="12.0(5)xk"/>
        <vers num="12.0(5)xk2"/>
        <vers num="12.0(5)xn"/>
        <vers num="12.0(5)xn1"/>
        <vers num="12.0(5)xs"/>
        <vers num="12.0(5)xu"/>
        <vers num="12.0(5)yb4"/>
        <vers num="12.0(5.1)xp"/>
        <vers num="12.0(5.2)xu"/>
        <vers num="12.0(5.3)wc1"/>
        <vers num="12.0(5.4)wc1"/>
        <vers num="12.0(6b)"/>
        <vers num="12.0(7)db2"/>
        <vers num="12.0(7)dc1"/>
        <vers num="12.0(7)s1"/>
        <vers num="12.0(7)sc"/>
        <vers num="12.0(7)t"/>
        <vers num="12.0(7)t2"/>
        <vers num="12.0(7)wx5(15a)"/>
        <vers num="12.0(7)xe"/>
        <vers num="12.0(7)xe2"/>
        <vers num="12.0(7)xf"/>
        <vers num="12.0(7)xf1"/>
        <vers num="12.0(7)xk"/>
        <vers num="12.0(7)xk3"/>
        <vers num="12.0(7)xv"/>
        <vers num="12.0(7.4)s"/>
        <vers num="12.0(7a)"/>
        <vers num="12.0(8)"/>
        <vers num="12.0(8)s1"/>
        <vers num="12.0(8.0.2)s"/>
        <vers num="12.0(8.3)sc"/>
        <vers num="12.0(8a)"/>
        <vers num="12.0(9)"/>
        <vers num="12.0(9)s"/>
        <vers num="12.0(9)s8"/>
        <vers num="12.0(9a)"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0t"/>
        <vers num="12.0w5"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0wx"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xu"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0101" published="2003-03-03" name="CVE-2003-0101" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2" source="CONFIRM" patch="1">http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610300325629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</ref>
      <ref url="http://www.securityfocus.com/bid/6915" source="BID">6915</ref>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/62_e.html" source="MISC">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</ref>
      <ref url="http://www.iss.net/security_center/static/11390.php" source="XF" adv="1">webmin-usermin-root-access(11390)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-319" source="DEBIAN">DSA-319</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-058.shtml" source="CIAC">N-058</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610336226274&amp;w=2" source="BUGTRAQ">20030224 GLSA:  usermin (200302-14)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610245624895&amp;w=2" source="BUGTRAQ">20030224 Webmin 1.050 - 1.060 remote exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html" source="ENGARDE">ESA-20030225-006</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html" source="HP">HPSBUX0303-250</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I" source="SGI">20030602-01-I</ref>
      <ref url="http://www.securitytracker.com/id?1006160" source="SECTRACK">1006160</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025" source="MANDRAKE">MDKSA-2003:025</ref>
      <ref url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html" source="CONFIRM">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</ref>
      <ref url="http://secunia.com/advisories/8163" source="SECUNIA">8163</ref>
      <ref url="http://secunia.com/advisories/8115" source="SECUNIA">8115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="engardelinux" name="guardian_digital_webtool">
        <vers num="1.2"/>
      </prod>
      <prod vendor="usermin" name="usermin">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.91"/>
        <vers num="0.92"/>
        <vers num="0.93"/>
        <vers num="0.94"/>
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.97"/>
        <vers num="0.98"/>
        <vers num="0.99"/>
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="1.0.50"/>
        <vers num="1.0.60"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0102" published="2003-03-18" name="CVE-2003-0102" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/611865" source="CERT-VN">VU#611865</ref>
      <ref url="http://www.securityfocus.com/bid/7008" source="BID" patch="1" adv="1">7008</ref>
      <ref url="http://www.idefense.com/advisory/03.04.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/03.04.03.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11469" source="XF">file-afctr-read-bo(11469)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-087.html" source="REDHAT">RHSA-2003:087</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-086.html" source="REDHAT">RHSA-2003:086</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_017_file.html" source="SUSE">SuSE-SA:2003:017</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030" source="MANDRAKE">MDKSA-2003:030</ref>
      <ref url="http://www.debian.org/security/2003/dsa-260" source="DEBIAN">DSA-260</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104680706201721&amp;w=2" source="BUGTRAQ">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</ref>
      <ref url="http://lwn.net/Alerts/34908/" source="IMMUNIX">IMNX-2003-7+-012-01</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc" source="NETBSD">NetBSD-SA2003-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="file" name="file">
        <vers num="3.28"/>
        <vers num="3.30"/>
        <vers num="3.32"/>
        <vers num="3.33"/>
        <vers num="3.34"/>
        <vers num="3.35"/>
        <vers num="3.36"/>
        <vers num="3.37"/>
        <vers num="3.39"/>
        <vers num="3.40"/>
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0103" published="2003-03-07" name="CVE-2003-0103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6952" source="BID" adv="1">6952</ref>
      <ref url="http://www.iss.net/security_center/static/11421.php" source="XF">nokia-6210-vcard-dos(11421)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="6210_handset">
        <vers num="5.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0104" published="2003-03-18" name="CVE-2003-0104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7053" source="BID" patch="1" adv="1">7053</ref>
      <ref url="http://www.iss.net/security_center/static/10962.php" source="XF" patch="1" adv="1">peoplesoft-schedulertransfer-create-files(10962)</ref>
      <ref url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999" source="ISS" patch="1" adv="1">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peoplesoft" name="peopletools">
        <vers num="8.10"/>
        <vers num="8.11"/>
        <vers num="8.12"/>
        <vers num="8.13"/>
        <vers num="8.14"/>
        <vers num="8.15"/>
        <vers num="8.16"/>
        <vers num="8.17"/>
        <vers num="8.18"/>
        <vers num="8.40"/>
        <vers num="8.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0105" published="2004-09-28" name="CVE-2003-0105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16947" source="XF" adv="1">servermask-header-obtain-info(16947)</ref>
      <ref url="http://www.corsaire.com/advisories/c030224-001.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c030224-001.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215441332682&amp;w=2" source="BUGTRAQ">20040810 Corsaire Security Advisory - Port80 Software ServerMask inconsistencies</ref>
    </refs>
    <vuln_soft>
      <prod vendor="port80_software" name="servermask">
        <vers prev="1" num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0106" published="2003-04-02" name="CVE-2003-0106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754" source="CONFIRM" patch="1" adv="1">http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869513822233&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref url="http://www.securityfocus.com/bid/7196" source="BID" adv="1">7196</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html" source="VULNWATCH">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104868285106289&amp;w=2" source="NTBUGTRAQ">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0107" published="2003-03-07" name="CVE-2003-0107" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/142121" source="CERT-VN">VU#142121</ref>
      <ref url="http://www.iss.net/security_center/static/11381.php" source="XF" adv="1">zlib-gzprintf-bo(11381)</ref>
      <ref url="http://online.securityfocus.com/archive/1/312869" source="BUGTRAQ">20030222 buffer overrun in zlib 1.1.4</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610337726297&amp;w=2" source="BUGTRAQ">20030223 poc zlib sploit just for fun :)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref url="http://www.securityfocus.com/bid/6913" source="BID">6913</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-081.html" source="REDHAT">RHSA-2003:081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-079.html" source="REDHAT">RHSA-2003:079</ref>
      <ref url="http://www.osvdb.org/6599" source="OSVDB">6599</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033" source="MANDRAKE">MDKSA-2003:033</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405" source="SUNALERT">57405</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887247624907&amp;w=2" source="GENTOO">GLSA-200303-25</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104620610427210&amp;w=2" source="BUGTRAQ">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610536129508&amp;w=2" source="BUGTRAQ">20030224 Re: buffer overrun in zlib 1.1.4</ref>
      <ref url="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619" source="CONECTIVA">CLSA-2003:619</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc" source="NETBSD">NetBSD-SA2003-004</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt" source="CALDERA">CSSA-2003-011.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zlib">
        <vers num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0108" published="2003-03-07" name="CVE-2003-0108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6974" source="BID" patch="1" adv="1">6974</ref>
      <ref url="http://www.idefense.com/advisory/02.27.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/02.27.03.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-255" source="DEBIAN" patch="1" adv="1">DSA-255</ref>
      <ref url="http://www.iss.net/security_center/static/11434.php" source="XF" adv="1">tcpdump-isakmp-dos(11434)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-214.html" source="REDHAT">RHSA-2003:214</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-085.html" source="REDHAT">RHSA-2003:085</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-032.html" source="REDHAT">RHSA-2003:032</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html" source="SUSE">SuSE-SA:2003:0015</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" source="MANDRAKE">MDKSA-2003:027</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104678787109030&amp;w=2" source="BUGTRAQ">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104637420104189&amp;w=2" source="BUGTRAQ">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629" source="CONECTIVA">CLA-2003:629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0109" published="2003-03-31" name="CVE-2003-0109" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-09.html" source="CERT" patch="1" adv="1">CA-2003-09</ref>
      <ref url="http://www.kb.cert.org/vuls/id/117394" source="CERT-VN">VU#117394</ref>
      <ref url="http://www.securityfocus.com/bid/7116" source="BID" patch="1" adv="1">7116</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-007.asp" source="MS" patch="1" adv="1">MS03-007</ref>
      <ref url="http://www.iss.net/security_center/static/11533.php" source="XF" patch="1" adv="1">http-webdav-long-request(11533)</ref>
      <ref url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029" source="ISS" patch="1" adv="1">20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability</ref>
      <ref url="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf" source="MISC">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q815021" source="MSKB">Q815021</ref>
      <ref url="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en" source="CONFIRM">http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104826785731151&amp;w=2" source="NTBUGTRAQ">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105768156625699&amp;w=2" source="BUGTRAQ">20030708 WDAV exploit without netcat and with pretty magic number</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887148323552&amp;w=2" source="BUGTRAQ">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869293619064&amp;w=2" source="BUGTRAQ">20030326 WebDAV exploit: using wide character decoder scheme</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861839130254&amp;w=2" source="BUGTRAQ">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826476427372&amp;w=2" source="BUGTRAQ">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:109" source="OVAL" sig="1">oval:org.mitre.oval:def:109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0110" published="2003-05-05" name="CVE-2003-0110" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-012.asp" source="MS" patch="1" adv="1">MS03-012</ref>
      <ref url="http://www.idefense.com/advisory/04.09.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/04.09.03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994487012027&amp;w=2" source="BUGTRAQ">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000 </ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:406" source="OVAL" sig="1">oval:org.mitre.oval:def:406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="fp1"/>
        <vers num="2000" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="proxy_server">
        <vers num="2.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0111" published="2003-05-05" name="CVE-2003-0111" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/447569" source="CERT-VN" patch="1" adv="1">VU#447569</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-011.asp" source="MS" patch="1" adv="1">MS03-011</ref>
      <ref url="http://www.iss.net/security_center/static/11751.php" source="XF" patch="1" adv="1">msvm-bytecode-improper-validation(11751)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:136" source="OVAL" sig="1">oval:org.mitre.oval:def:136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_machine">
        <vers num="3802"/>
        <vers num="3805"/>
        <vers num="3809"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0112" published="2003-05-12" name="CVE-2003-0112" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/446338" source="CERT-VN">VU#446338</ref>
      <ref url="http://www.securityfocus.com/bid/7370" source="BID" patch="1" adv="1">7370</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-013.asp" source="MS" patch="1" adv="1">MS03-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11803" source="XF">win-kernel-lpcrequestwaitreplyport-bo(11803)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:779" source="OVAL" sig="1">oval:org.mitre.oval:def:779</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3145" source="OVAL" sig="1">oval:org.mitre.oval:def:3145</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:262" source="OVAL" sig="1">oval:org.mitre.oval:def:262</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2265" source="OVAL" sig="1">oval:org.mitre.oval:def:2265</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2022" source="OVAL" sig="1">oval:org.mitre.oval:def:2022</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:142" source="OVAL" sig="1">oval:org.mitre.oval:def:142</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1264" source="OVAL" sig="1">oval:org.mitre.oval:def:1264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0113" published="2003-05-12" name="CVE-2003-0113" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/169753" source="CERT-VN">VU#169753</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105138417416900&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030426 Buffer overflow in Internet Explorer's HTTP parsing code</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718285107246&amp;w=2" source="BUGTRAQ">20030701 URLMON.DLL buffer overflow - technical details</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:926" source="OVAL" sig="1">oval:org.mitre.oval:def:926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0114" published="2003-05-12" name="CVE-2003-0114" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104429340817718&amp;w=2" source="BUGTRAQ" adv="1">20030203 internet explorer local file reading</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:963" source="OVAL" sig="1">oval:org.mitre.oval:def:963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0115" published="2003-05-12" name="CVE-2003-0115" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://www.iss.net/security_center/static/11848.php" source="XF" adv="1">ie-improper-thirdparty-rendering(11848)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0116" published="2003-05-12" name="CVE-2003-0116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/244729" source="CERT-VN">VU#244729</ref>
      <ref url="http://www.securityfocus.com/bid/6306" source="BID" patch="1" adv="1">6306</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://www.securityfocus.com/archive/1/301945" source="BUGTRAQ">20021203 Poisonous Style for Dialog window turns the zone off.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0117" published="2003-05-12" name="CVE-2003-0117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" source="MS" patch="1" adv="1">MS03-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216866132289&amp;w=2" source="BUGTRAQ">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":enterprise"/>
        <vers num="2002" edition=":developer"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0118" published="2003-05-12" name="CVE-2003-0118" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" source="MS" patch="1" adv="1">MS03-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216839231951&amp;w=2" source="BUGTRAQ">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2000" edition=""/>
        <vers num="2000" edition=":standard"/>
        <vers num="2000" edition=":developer"/>
        <vers num="2000" edition=":enterprise"/>
        <vers num="2000" edition="sp1a"/>
        <vers num="2000" edition="sp1a:developer"/>
        <vers num="2000" edition="sp1a:enterprise"/>
        <vers num="2000" edition="sp1a:standard"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp2:standard"/>
        <vers num="2000" edition="sp2:enterprise"/>
        <vers num="2000" edition="sp2:developer"/>
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":enterprise"/>
        <vers num="2002" edition=":developer"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0119" published="2004-02-03" name="CVE-2003-0119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/624713" source="CERT-VN" patch="1" adv="1">VU#624713</ref>
      <ref url="http://www.securityfocus.com/bid/7264" source="BID" patch="1" adv="1">7264</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/4699c03b46f2d4f68525678c006d45ae/85256a3400529a8685256cde0008ddde?OpenDocument" source="IBM">MSS-OAR-E01-2003:0245.1</ref>
      <ref url="http://secunia.com/advisories/8221" source="SECUNIA">8221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0120" published="2003-03-07" name="CVE-2003-0120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-256" source="DEBIAN" patch="1" adv="1">DSA-256</ref>
      <ref url="http://www.securityfocus.com/bid/6978" source="BID">6978</ref>
      <ref url="http://www.iss.net/security_center/static/11439.php" source="XF">mhc-adb2mhc-insecure-tmp(11439)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhc-utils" name="mhc-utils">
        <vers num="0.25_snap2001-06-25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0121" published="2003-03-18" name="CVE-2003-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7044" source="BID" patch="1" adv="1">7044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716030503607&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/316311" source="BUGTRAQ">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0122" published="2003-03-18" name="CVE-2003-0122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/433489" source="CERT-VN">VU#433489</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/7037" source="BID" patch="1" adv="1">7037</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757319829443&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0010.html" source="MISC">http://www.rapid7.com/advisories/R7-0010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11526" source="XF">lotus-nrpc-bo(11526)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html" source="VULNWATCH">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="4.6.1"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4" edition=""/>
        <vers num="5.0.4" edition=":solaris"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5" edition=""/>
        <vers num="5.0.5" edition=":"/>
        <vers num="5.0.5" edition="::french"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7" edition=""/>
        <vers num="5.0.7" edition=":solaris"/>
        <vers num="5.0.7a"/>
        <vers num="5.0.8" edition=""/>
        <vers num="5.0.8" edition=":"/>
        <vers num="5.0.8" edition="::french"/>
        <vers num="5.0.8a"/>
        <vers num="5.0.9"/>
        <vers num="5.0.9a"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes_client">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.9a"/>
        <vers num="r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0123" published="2003-03-18" name="CVE-2003-0123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/411489" source="CERT-VN">VU#411489</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/7038" source="BID" patch="1" adv="1">7038</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757545500368&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0011.html" source="MISC">http://www.rapid7.com/advisories/R7-0011.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11525" source="XF">lotus-web-retriever-bo(11525)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="4.6.1"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4" edition=""/>
        <vers num="5.0.4" edition=":solaris"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5" edition=""/>
        <vers num="5.0.5" edition=":"/>
        <vers num="5.0.5" edition="::french"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7" edition=""/>
        <vers num="5.0.7" edition=":solaris"/>
        <vers num="5.0.7a"/>
        <vers num="5.0.8" edition=""/>
        <vers num="5.0.8" edition=":"/>
        <vers num="5.0.8" edition="::french"/>
        <vers num="5.0.8a"/>
        <vers num="5.0.9"/>
        <vers num="5.0.9a"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes_client">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.9a"/>
        <vers num="r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0124" published="2003-03-18" name="CVE-2003-0124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7066" source="BID" patch="1" adv="1">7066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104740927915154&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030311 Vulnerability in man &lt; 1.5l</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11512" source="XF">man-myxsprintf-code-execution(11512)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-134.html" source="REDHAT">RHSA-2003:134</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-133.html" source="REDHAT">RHSA-2003:133</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285112752&amp;w=2" source="GENTOO">GLSA-200303-13</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620" source="CONECTIVA">CLSA-2003:620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="man">
        <vers num="1.5h1"/>
        <vers num="1.5i"/>
        <vers num="1.5i2"/>
        <vers num="1.5j"/>
        <vers num="1.5k"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0125" published="2003-03-18" name="CVE-2003-0125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" source="MISC" patch="1" adv="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
      <ref url="ftp://ftp.multitech.com/Routers/RF550VPN.TXT" source="CONFIRM" adv="1">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11514" source="XF">routefinder-vpn-options-bo(11514)</ref>
      <ref url="http://www.securityfocus.com/bid/7067" source="BID">7067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="multitech" name="routefinder_550_vpn">
        <vers prev="1" num="4.63"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0126" published="2003-03-18" name="CVE-2003-0126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" source="MISC" patch="1" adv="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="multitech" name="routefinder_550_vpn">
        <vers prev="1" num="4.63"/>
        <vers num="4.64_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0127" published="2003-03-31" name="CVE-2003-0127" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/628849" source="CERT-VN" adv="1">VU#628849</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-098.html" source="REDHAT" patch="1" adv="1">RHSA-2003:098</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-145.html" source="REDHAT">RHSA-2003:145</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN">DSA-423</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN">DSA-311</ref>
      <ref url="http://www.debian.org/security/2003/dsa-276" source="DEBIAN">DSA-276</ref>
      <ref url="http://www.debian.org/security/2003/dsa-270" source="DEBIAN">DSA-270</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200303-17.xml" source="GENTOO">GLSA-200303-17</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-088.html" source="REDHAT">RHSA-2003:088</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt" source="CALDERA">CSSA-2003-020.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-103.html" source="REDHAT">RHSA-2003:103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039" source="MANDRAKE">MDKSA-2003:039</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038" source="MANDRAKE">MDKSA-2003:038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" source="ENGARDE">ESA-20030515-017</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html" source="VULNWATCH">20030317 Fwd: Ptrace hole / Linux 2.2.25</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:254" source="OVAL" sig="1">oval:org.mitre.oval:def:254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers num="2.2.16"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.2.22"/>
        <vers num="2.2.23"/>
        <vers num="2.2.24"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0128" published="2003-03-24" name="CVE-2003-0128" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7117" source="BID" patch="1" adv="1">7117</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-108.html" source="REDHAT">RHSA-2003:108</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" source="BUGTRAQ">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" source="MANDRAKE">MDKSA-2003:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" source="GENTOO">GLSA-200303-18</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" source="BUGTRAQ">20030321 GLSA:  evolution (200303-18)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" source="CONECTIVA">CLA-2003:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:107" source="OVAL" sig="1">oval:org.mitre.oval:def:107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0129" published="2003-03-24" name="CVE-2003-0129" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7118" source="BID" patch="1" adv="1">7118</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030321 GLSA:  evolution (200303-18)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-108.html" source="REDHAT">RHSA-2003:108</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" source="BUGTRAQ">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" source="MANDRAKE">MDKSA-2003:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" source="GENTOO">GLSA-200303-18</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" source="CONECTIVA">CLA-2003:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:108" source="OVAL" sig="1">oval:org.mitre.oval:def:108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0130" published="2003-03-24" name="CVE-2003-0130" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7119" source="BID" patch="1" adv="1">7119</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030321 GLSA:  evolution (200303-18)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-108.html" source="REDHAT">RHSA-2003:108</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html" source="BUGTRAQ">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045" source="MANDRAKE">MDKSA-2003:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml" source="GENTOO">GLSA-200303-18</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648" source="CONECTIVA">CLA-2003:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:111" source="OVAL" sig="1">oval:org.mitre.oval:def:111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0131" published="2003-03-24" name="CVE-2003-0131" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/888801" source="CERT-VN" adv="1">VU#888801</ref>
      <ref url="http://www.securityfocus.com/bid/7148" source="BID" patch="1" adv="1">7148</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811162730834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11586" source="XF" adv="1">ssl-premaster-information-leak(11586)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="BUGTRAQ">20030327 Immunix Secured OS 7+ openssl update</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-102.html" source="REDHAT">RHSA-2003:102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-101.html" source="REDHAT">RHSA-2003:101</ref>
      <ref url="http://www.openssl.org/news/secadv_20030319.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20030319.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_024_openssl.html" source="SUSE">SuSE-SA:2003:024</ref>
      <ref url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" source="MISC">http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html</ref>
      <ref url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html" source="IMMUNIX">IMNX-2003-7+-001-01</ref>
      <ref url="http://www.debian.org/security/2003/dsa-288" source="DEBIAN">DSA-288</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref url="http://eprint.iacr.org/2003/052/" source="MISC" adv="1">http://eprint.iacr.org/2003/052/</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" source="SGI">20030501-01-I</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc" source="NETBSD">NetBSD-SA2003-007</ref>
      <ref url="http://www.suse.de/de/security/2003_024_openssl.html" source="SUSE">SuSE-SA:2003:024</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="BUGTRAQ">20030327 Immunix Secured OS 7+ openssl update</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html" source="OPENPKG">OpenPKG-SA-2003.026</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035" source="MANDRAKE">MDKSA-2003:035</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml" source="GENTOO">GLSA-200303-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878215721135&amp;w=2" source="TRUSTIX">2003-0013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852637112330&amp;w=2" source="BUGTRAQ">20030324 GLSA:  openssl (200303-20)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" source="CONECTIVA">CLA-2003:625</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" source="CALDERA">CSSA-2003-014.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:461" source="OVAL" sig="1">oval:org.mitre.oval:def:461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.7"/>
        <vers num="0.9.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0132" published="2003-04-11" name="CVE-2003-0132" modified="2009-05-13" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/206537" source="CERT-VN">VU#206537</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1233" source="VUPEN">ADV-2009-1233</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-139.html" source="REDHAT">RHSA-2003:139</ref>
      <ref url="http://www.idefense.com/advisory/04.08.03.txt" source="MISC">http://www.idefense.com/advisory/04.08.03.txt</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147" source="MISC">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</ref>
      <ref url="http://secunia.com/advisories/8499" source="SECUNIA">8499</ref>
      <ref url="http://secunia.com/advisories/34920" source="SECUNIA">34920</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013378320711&amp;w=2" source="BUGTRAQ">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001663120995&amp;w=2" source="BUGTRAQ">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994309010974&amp;w=2" source="BUGTRAQ">20030408 Exploit Code Released for Apache 2.x Memory Leak</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994239010517&amp;w=2" source="BUGTRAQ">20030409 GLSA:  apache (200304-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104982175321731&amp;w=2" source="BUGTRAQ">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156" source="OVAL" sig="1">oval:org.mitre.oval:def:156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0133" published="2003-05-05" name="CVE-2003-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-126.html" source="REDHAT" patch="1" adv="1">RHSA-2003:126</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046" source="MANDRAKE">MDKSA-2003:046</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" source="CONECTIVA">CLA-2003:737</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:138" source="OVAL" sig="1">oval:org.mitre.oval:def:138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gtkhtml">
        <vers num="1.1.10"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0134" published="2003-04-11" name="CVE-2003-0134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
      <ref url="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35" source="CONFIRM" patch="1">http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" source="BUGTRAQ">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0135" published="2003-04-11" name="CVE-2003-0135" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7253" source="BID" patch="1" adv="1">7253</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-084.html" source="REDHAT" patch="1" adv="1">RHSA-2003:084</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:634" source="OVAL" sig="1">oval:org.mitre.oval:def:634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0136" published="2003-05-05" name="CVE-2003-0136" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-142.html" source="REDHAT" patch="1" adv="1">RHSA-2003:142</ref>
      <ref url="http://www.debian.org/security/2003/dsa-285" source="DEBIAN" patch="1" adv="1">DSA-285</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:423" source="OVAL" sig="1">oval:org.mitre.oval:def:423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astart_technologies" name="lprng">
        <vers num="3.7.4"/>
        <vers num="3.8.10.1"/>
        <vers num="3.8.19"/>
        <vers num="3.8.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0137" published="2003-03-18" name="CVE-2003-0137" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a031303-2.txt" source="ATSTAKE" adv="1">A031303-2</ref>
      <ref url="http://secunia.com/advisories/8301" source="SECUNIA">8301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="sgsn_dx200">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0138" published="2003-03-24" name="CVE-2003-0138" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/623217" source="CERT-VN" patch="1" adv="1">VU#623217</ref>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN" patch="1" adv="1">DSA-266</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.debian.org/security/2003/dsa-273" source="DEBIAN">DSA-273</ref>
      <ref url="http://www.debian.org/security/2003/dsa-269" source="DEBIAN">DSA-269</ref>
      <ref url="http://www.securityfocus.com/bid/7113" source="BID">7113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" source="BUGTRAQ">20030317 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 protocol</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:248" source="OVAL" sig="1">oval:org.mitre.oval:def:248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0139" published="2003-03-24" name="CVE-2003-0139" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/442569" source="CERT-VN" patch="1" adv="1">VU#442569</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-091.html" source="REDHAT">RHSA-2003:091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-052.html" source="REDHAT">RHSA-2003:052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-051.html" source="REDHAT">RHSA-2003:051</ref>
      <ref url="http://www.debian.org/security/2003/dsa-273" source="DEBIAN">DSA-273</ref>
      <ref url="http://www.debian.org/security/2003/dsa-266" source="DEBIAN">DSA-266</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317130/30/25250/threaded" source="BUGTRAQ">20030330 GLSA: openafs (200303-26)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:250" source="OVAL" sig="1">oval:org.mitre.oval:def:250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0140" published="2003-03-24" name="CVE-2003-0140" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7120" source="BID" patch="1" adv="1">7120</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104818814931378&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11583" source="XF" adv="1">mutt-folder-name-bo(11583)</ref>
      <ref url="http://www.securityfocus.com/archive/1/315679" source="BUGTRAQ" adv="1">20030319 mutt-1.4.1 fixes a buffer overflow.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-109.html" source="REDHAT">RHSA-2003:109</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_020_mutt.html" source="SUSE">SuSE-SA:2003:020</ref>
      <ref url="http://www.debian.org/security/2003/dsa-268" source="DEBIAN">DSA-268</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041" source="MANDRAKE">MDKSA-2003:041</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml" source="GENTOO">GLSA-200303-19</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105171507629573&amp;w=2" source="BUGTRAQ">20030430 GLSA:  balsa (200304-10)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852190605988&amp;w=2" source="BUGTRAQ">20030322 GLSA:  mutt (200303-19)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104817995421439&amp;w=2" source="BUGTRAQ">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630" source="CONECTIVA">CLA-2003:630</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626" source="CONECTIVA">CLA-2003:626</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:434" source="OVAL" sig="1">oval:org.mitre.oval:def:434</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2" source="OVAL" sig="1">oval:org.mitre.oval:def:2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.3.12"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.22"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.27"/>
        <vers num="1.4.0"/>
        <vers num="1.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0141" published="2003-04-02" name="CVE-2003-0141" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/705761" source="CERT-VN" adv="1">VU#705761</ref>
      <ref url="http://www.securityfocus.com/bid/7177" source="BID" patch="1" adv="1">7177</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887465427579&amp;w=2" source="BUGTRAQ">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html" source="VULNWATCH">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774"/>
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="2.0"/>
        <vers num="6.0.10.505" edition="gold"/>
        <vers num="6.0.11.818"/>
        <vers num="6.0.11.830"/>
        <vers num="6.0.11.841"/>
        <vers num="6.0.11.853"/>
        <vers num="9.0.0.288"/>
        <vers num="9.0.0.297"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0142" published="2003-08-18" name="CVE-2003-0142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/689835" source="CERT-VN">VU#689835</ref>
      <ref url="http://www.securityfocus.com/archive/1/328224" source="BUGTRAQ" adv="1">20030708 Adobe Acrobat and PDF security: no improvements for 2 years</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0143" published="2003-03-18" name="CVE-2003-0143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7058" source="BID" patch="1" adv="1">7058</ref>
      <ref url="http://www.debian.org/security/2003/dsa-259" source="DEBIAN" patch="1" adv="1">DSA-259</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11516" source="XF" adv="1">qpopper-popmsg-macroname-bo(11516)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739841223916&amp;w=2" source="BUGTRAQ" adv="1">20030310 QPopper 4.0.x buffer overflow vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html" source="SUSE">SuSE-SA:2003:018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792541215354&amp;w=2" source="GENTOO">GLSA-200303-12</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104768137314397&amp;w=2" source="BUGTRAQ">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104748775900481&amp;w=2" source="BUGTRAQ">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0144" published="2003-03-31" name="CVE-2003-0144" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7025" source="BID" patch="1" adv="1">7025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11473" source="XF" adv="1">lprm-bo(11473)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_014_lprold.html" source="SUSE">SuSE-SA:2003:0014</ref>
      <ref url="http://www.debian.org/security/2003/dsa-275" source="DEBIAN">DSA-275</ref>
      <ref url="http://www.debian.org/security/2003/dsa-267" source="DEBIAN">DSA-267</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P" source="SGI">20030406-02-P</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch" source="CONFIRM">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059" source="MANDRAKE">MDKSA-2003:059</ref>
      <ref url="http://secunia.com/advisories/8293" source="SECUNIA">8293</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104714441925019&amp;w=2" source="BUGTRAQ">20030308 OpenBSD lprm(1) exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104690434504429&amp;w=2" source="BUGTRAQ">20030305 potential buffer overflow in lprm (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lprold" name="lprold">
        <vers num="3.0.48"/>
      </prod>
      <prod vendor="bsd" name="lpr">
        <vers num="0.48"/>
        <vers num="2000-05-07"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0145" published="2003-03-31" name="CVE-2003-0145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.tcpdump.org/tcpdump-changes.txt" source="CONFIRM" adv="1">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11857" source="XF">tcpdump-radius-attribute-dos(11857)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-214.html" source="REDHAT">RHSA-2003:214</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-151.html" source="REDHAT">RHSA-2003:151</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-032.html" source="REDHAT">RHSA-2003:032</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027" source="MANDRAKE">MDKSA-2003:027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-261" source="DEBIAN">DSA-261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0146" published="2003-03-31" name="CVE-2003-0146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/630433" source="CERT-VN">VU#630433</ref>
      <ref url="http://www.debian.org/security/2003/dsa-263" source="DEBIAN" patch="1" adv="1">DSA-263</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11463" source="XF">netpbm-multiple-bo(11463)</ref>
      <ref url="http://www.securityfocus.com/bid/6979" source="BID">6979</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-060.html" source="REDHAT">RHSA-2003:060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104644687816522&amp;w=2" source="BUGTRAQ" adv="1">20030228 NetPBM, multiple vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656" source="CONECTIVA">CLSA-2003:656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netpbm" name="netpbm">
        <vers prev="1" num="9.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0147" published="2003-03-31" name="CVE-2003-0147" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/997481" source="CERT-VN" adv="1">VU#997481</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="BUGTRAQ">20030327 Immunix Secured OS 7+ openssl update</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-102.html" source="REDHAT">RHSA-2003:102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-101.html" source="REDHAT">RHSA-2003:101</ref>
      <ref url="http://www.openssl.org/news/secadv_20030317.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20030317.txt</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035" source="MANDRAKE">MDKSA-2003:035</ref>
      <ref url="http://www.debian.org/security/2003/dsa-288" source="DEBIAN">DSA-288</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792570615648&amp;w=2" source="BUGTRAQ" adv="1">20030317 [ADVISORY] Timing Attack on OpenSSL</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766550528628&amp;w=2" source="BUGTRAQ" adv="1">20030313 Vulnerability in OpenSSL</ref>
      <ref url="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf" source="MISC">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html" source="VULNWATCH" adv="1">20030313 OpenSSL Private Key Disclosure</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I" source="SGI">20030501-01-I</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded" source="IMMUNIX">IMNX-2003-7+-001-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded" source="BUGTRAQ">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html" source="OPENPKG">OpenPKG-SA-2003.019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml" source="GENTOO">GLSA-200303-23</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861762028637&amp;w=2" source="GENTOO">GLSA-200303-24</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104829040921835&amp;w=2" source="GENTOO">GLSA-200303-15</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104819602408063&amp;w=2" source="BUGTRAQ">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625" source="CONECTIVA">CLA-2003:625</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt" source="CALDERA">CSSA-2003-014.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:466" source="OVAL" sig="1">oval:org.mitre.oval:def:466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.1"/>
        <vers num="1.2"/>
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.7"/>
        <vers num="0.9.7a"/>
      </prod>
      <prod vendor="stunnel" name="stunnel">
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.17"/>
        <vers num="3.18"/>
        <vers num="3.19"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.22"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="4.02"/>
        <vers num="4.03"/>
        <vers num="4.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0148" published="2003-08-27" name="CVE-2003-0148" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" source="CONFIRM" patch="1" adv="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" source="ATSTAKE" patch="1" adv="1">A073103-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0149" published="2003-08-27" name="CVE-2003-0149" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" source="CONFIRM" patch="1" adv="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" source="ATSTAKE" patch="1" adv="1">A073103-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0150" published="2003-03-24" name="CVE-2003-0150" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/203897" source="CERT-VN">VU#203897</ref>
      <ref url="http://www.securityfocus.com/bid/7052" source="BID" patch="1" adv="1">7052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11510" source="XF">mysql-datadir-root-privileges(11510)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-093.html" source="REDHAT">RHSA-2003:093</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html" source="ENGARDE">ESA-20030324-012</ref>
      <ref url="http://www.debian.org/security/2003/dsa-303" source="DEBIAN">DSA-303</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-094.html" source="REDHAT">RHSA-2003:094</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285012750&amp;w=2" source="BUGTRAQ">20030318 GLSA:  mysql (200303-14)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739810523433&amp;w=2" source="BUGTRAQ">20030310 Re: MySQL user can be changed to root</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2" source="BUGTRAQ">20030308 MySQL_user_can_be_changed_to_root?</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743" source="CONECTIVA">CLA-2003:743</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057" source="MANDRAKE">MDKSA-2003:057</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:442" source="OVAL" sig="1">oval:org.mitre.oval:def:442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.53a"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
        <vers num="3.23.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0151" published="2003-03-24" name="CVE-2003-0151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792544515384&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792477914620&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030317 SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express</ref>
      <ref url="http://www.s21sec.com/en/avisos/s21sec-011-en.txt" source="MISC">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</ref>
      <ref url="http://www.securityfocus.com/bid/7124" source="BID">7124</ref>
      <ref url="http://www.securityfocus.com/bid/7122" source="BID">7122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":express"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp1:express"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp2:express"/>
        <vers num="6.1" edition=""/>
        <vers num="6.1" edition=":express"/>
        <vers num="6.1" edition="sp1"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp2"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp3"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp4"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0.0.1" edition=""/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition="sp1"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp2"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0152" published="2003-04-02" name="CVE-2003-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7162" source="BID" patch="1" adv="1">7162</ref>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0153" published="2003-04-02" name="CVE-2003-0153" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/9921" source="XF">bonsai-path-disclosure(9921)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" source="BUGTRAQ" adv="1">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=187230" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</ref>
      <ref url="http://www.securityfocus.com/bid/5517" source="BID">5517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0154" published="2003-04-02" name="CVE-2003-0154" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/5516" source="BID" patch="1" adv="1">5516</ref>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
      <ref url="http://www.iss.net/security_center/static/9920.php" source="XF">bonsai-error-message-xss(9920)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" source="BUGTRAQ" adv="1">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=163573" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=146244" source="MISC">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</ref>
      <ref url="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view" source="CONFIRM">http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view</ref>
      <ref url="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view" source="CONFIRM">http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0155" published="2003-04-02" name="CVE-2003-0155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7163" source="BID" patch="1" adv="1">7163</ref>
      <ref url="http://www.debian.org/security/2003/dsa-265" source="DEBIAN" patch="1" adv="1">DSA-265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bonsai">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0156" published="2003-03-24" name="CVE-2003-0156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7062" source="BID" patch="1" adv="1">7062</ref>
      <ref url="http://www.debian.org/security/2003/dsa-264" source="DEBIAN" patch="1" adv="1">DSA-264</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739747222492&amp;w=2" source="BUGTRAQ" adv="1">20030311 Cross-Referencing Linux vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cross_referencer" name="lxr">
        <vers num="0.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0157" reject="1" published="2003-03-24" name="CVE-2003-0157" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" seq="2003-0158" reject="1" published="2003-03-24" name="CVE-2003-0158" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0159" published="2003-04-02" name="CVE-2003-0159" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7050" source="BID" patch="1" adv="1">7050</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html" source="SUSE">SuSE-SA:2003:019</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051" source="MANDRAKE">MDKSA-2003:051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104741640924709&amp;w=2" source="BUGTRAQ">20030309 GLSA:  ethereal (200303-10)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:55" source="OVAL" sig="1">oval:org.mitre.oval:def:55</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.8.18"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0160" published="2003-04-02" name="CVE-2003-0160" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988" source="CONFIRM" patch="1">http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-112.html" source="REDHAT">RHSA-2003:112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:614" source="OVAL" sig="1">oval:org.mitre.oval:def:614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers prev="1" num="1.2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0161" published="2003-04-02" name="CVE-2003-0161" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-12.html" source="CERT" patch="1" adv="1">CA-2003-12</ref>
      <ref url="http://www.kb.cert.org/vuls/id/897604" source="CERT-VN">VU#897604</ref>
      <ref url="http://www.securityfocus.com/bid/7230" source="BID" patch="1" adv="1">7230</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-120.html" source="REDHAT" patch="1" adv="1">RHSA-2003:120</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-002-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-121.html" source="REDHAT">RHSA-2003:121</ref>
      <ref url="http://www.debian.org/security/2003/dsa-290" source="DEBIAN">DSA-290</ref>
      <ref url="http://www.debian.org/security/2003/dsa-278" source="DEBIAN">DSA-278</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001088.1-1" source="SUNALERT">1001088</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104897487512238&amp;w=2" source="BUGTRAQ" adv="1">20030329 Sendmail: -1 gone wild</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html" source="FULLDISC">20030329 Sendmail: -1 gone wild</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P" source="SGI">20030401-01-P</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt" source="SCO">SCOSA-2004.11</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc" source="FREEBSD">FreeBSD-SA-03:07</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt" source="CALDERA">CSSA-2003-016.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded" source="IMMUNIX">IMNX-2003-7+-002-01</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/316961/30/25250/threaded" source="BUGTRAQ">20030331 GLSA: sendmail (200303-27)</ref>
      <ref url="http://www.securityfocus.com/archive/1/321997" source="BUGTRAQ">20030520 [Fwd: 127 Research and Development: 127 Day!]</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml" source="GENTOO">GLSA-200303-27</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1" source="SUNALERT">52700</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1" source="SUNALERT">52620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914999806315&amp;w=2" source="BUGTRAQ">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104896621106790&amp;w=2" source="BUGTRAQ">20030329 sendmail 8.12.9 available</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614" source="CONECTIVA">CLA-2003:614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="8.10"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
        <vers num="8.11.0"/>
        <vers num="8.11.1"/>
        <vers num="8.11.2"/>
        <vers num="8.11.3"/>
        <vers num="8.11.4"/>
        <vers num="8.11.5"/>
        <vers num="8.11.6"/>
        <vers num="8.12" edition="beta10"/>
        <vers num="8.12" edition="beta12"/>
        <vers num="8.12" edition="beta16"/>
        <vers num="8.12" edition="beta5"/>
        <vers num="8.12" edition="beta7"/>
        <vers num="8.12.0"/>
        <vers num="8.12.1"/>
        <vers num="8.12.2"/>
        <vers num="8.12.3"/>
        <vers num="8.12.4"/>
        <vers num="8.12.5"/>
        <vers num="8.12.6"/>
        <vers num="8.12.7"/>
        <vers num="8.12.8"/>
        <vers num="8.9.0"/>
        <vers num="8.9.1"/>
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
      </prod>
      <prod vendor="sendmail" name="sendmail_switch">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0b"/>
        <vers num="4.0d"/>
        <vers num="4.0d_pk9_bl17"/>
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="5.0"/>
        <vers num="5.0_pk4_bl17"/>
        <vers num="5.0_pk4_bl18"/>
        <vers num="5.0a"/>
        <vers num="5.0a_pk3_bl17"/>
        <vers num="5.0f"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.0.4"/>
        <vers num="11.00"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod vendor="hp" name="hp-ux_series_700">
        <vers num="10.20"/>
      </prod>
      <prod vendor="hp" name="hp-ux_series_800">
        <vers num="10.20"/>
      </prod>
      <prod vendor="hp" name="sis">
        <vers num=""/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition=""/>
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=""/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=""/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":x86"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0162" published="2003-04-02" name="CVE-2003-0162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6971" source="BID" patch="1" adv="1">6971</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11431" source="XF" adv="1">ecartis-password-reset(11431)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-271" source="DEBIAN">DSA-271</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673407728323&amp;w=2" source="BUGTRAQ" adv="1">20030303 Re: Ecardis Password Reseting Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636153214262&amp;w=2" source="BUGTRAQ">20030227 Ecardis Password Reseting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="1.0.0_snapshot_2002-10-13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0163" published="2003-05-05" name="CVE-2003-0163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7182" source="BID" patch="1" adv="1">7182</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0013.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0013.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013281120352&amp;w=2" source="BUGTRAQ">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gaim-encryption" name="gaim-encryption">
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0165" published="2003-04-02" name="CVE-2003-0165" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/363001" source="CERT-VN">VU#363001</ref>
      <ref url="http://www.securityfocus.com/bid/7121" source="BID" patch="1" adv="1">7121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-128.html" source="REDHAT" patch="1" adv="1">RHSA-2003:128</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887189724146&amp;w=2" source="BUGTRAQ">20030328 CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html" source="VULNWATCH">20030328 Vulnerability in GNOME's Eye of Gnome</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048" source="MANDRAKE">MDKSA-2003:048</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:52" source="OVAL" sig="1">oval:org.mitre.oval:def:52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="eog">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0166" published="2003-04-02" name="CVE-2003-0166" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7198" source="BID" adv="1">7198</ref>
      <ref url="http://www.securityfocus.com/bid/7197" source="BID" adv="1">7197</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869828526885&amp;w=2" source="BUGTRAQ" adv="1">20030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2" source="BUGTRAQ">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878100719467&amp;w=2" source="BUGTRAQ">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" source="CONECTIVA">CLSA-2003:691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0167" published="2003-04-02" name="CVE-2003-0167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7229" source="BID" patch="1" adv="1">7229</ref>
      <ref url="http://www.debian.org/security/2003/dsa-274" source="DEBIAN" patch="1" adv="1">DSA-274</ref>
      <ref url="http://www.debian.org/security/2003/dsa-300" source="DEBIAN">DSA-300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.3.12"/>
        <vers num="1.3.12.1"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.22"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0168" published="2003-04-02" name="CVE-2003-0168" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/112553" source="CERT-VN">VU#112553</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded" source="BUGTRAQ">20030401 Fwd: QuickTime 6.1 for Windows is available</ref>
      <ref url="http://www.idefense.com/advisory/03.31.03.txt" source="MISC">http://www.idefense.com/advisory/03.31.03.txt</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00027.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00027.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html" source="VULNWATCH" adv="1">20030331 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11671" source="XF">quicktime-url-bo(11671)</ref>
      <ref url="http://www.securityfocus.com/bid/7247" source="BID">7247</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317148/30/25220/threaded" source="BUGTRAQ">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded" source="BUGTRAQ">20030401 Fwd: QuickTime 6.1 for Windows is available</ref>
      <ref url="http://www.osvdb.org/10561" source="OSVDB">10561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0169" published="2003-04-11" name="CVE-2003-0169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7246" source="BID" patch="1" adv="1">7246</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html" source="VULNWATCH" patch="1" adv="1">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914959705949&amp;w=2" source="BUGTRAQ">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="instant_toptools">
        <vers num="5.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0170" published="2004-03-29" name="CVE-2003-0170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11823" source="XF" patch="1" adv="1">aix-ftpd-gain-access(11823)</ref>
      <ref url="http://www.securityfocus.com/bid/7346" source="BID" patch="1" adv="1">7346</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY42424" source="AIXAPAR" patch="1" adv="1">IY42424</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0469.1" source="IBM">MSS-OAR-E01-2003.0469.1</ref>
      <ref url="http://www.osvdb.org/4878" source="OSVDB">4878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0171" published="2003-05-05" name="CVE-2003-0171" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a041003-1.txt" source="ATSTAKE" adv="1">A041003-1</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0172" published="2003-04-02" name="CVE-2003-0172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7210" source="BID" patch="1" adv="1">7210</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878149020152&amp;w=2" source="BUGTRAQ" adv="1">20030327 @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11637" source="XF">php-openlog-stack-bo(11637)</ref>
      <ref url="http://www.securityfocus.com/archive/1/385238" source="BUGTRAQ">20041222 PHP v4.3.x exploit for Windows.</ref>
      <ref url="http://www.securityfocus.com/archive/1/316583" source="BUGTRAQ">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
      <ref url="http://www.osvdb.org/2113" source="OSVDB">2113</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2" source="BUGTRAQ">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0173" published="2003-05-05" name="CVE-2003-0173" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/111673" source="CERT-VN">VU#111673</ref>
      <ref url="http://www.debian.org/security/2003/dsa-283" source="DEBIAN" patch="1" adv="1">DSA-283</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P" source="SGI" patch="1" adv="1">20030404-01-P</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047" source="MANDRAKE">MDKSA-2003:047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfsdump" name="xfsdump">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0174" published="2003-05-12" name="CVE-2003-0174" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7442" source="BID" patch="1" adv="1">7442</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P" source="SGI" patch="1" adv="1">20030407-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11860" source="XF">irix-ldap-authentication-bypass(11860)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-084.shtml" source="CIAC">N-084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0175" published="2004-02-03" name="CVE-2003-0175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/142228" source="CERT-VN" patch="1" adv="1">VU#142228</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12241" source="XF" patch="1" adv="1">irix-piocswatch-ioctl-dos(12241)</ref>
      <ref url="http://www.securityfocus.com/bid/7868" source="BID" patch="1" adv="1">7868</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P" source="SGI" patch="1" adv="1">20030603-01-P</ref>
      <ref url="http://www.securitytracker.com/id?1008770" source="SECTRACK">1008770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0176" published="2003-08-18" name="CVE-2003-0176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0177" published="2003-08-18" name="CVE-2003-0177" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0178" published="2003-04-02" name="CVE-2003-0178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/772817" source="CERT-VN" patch="1" adv="1">VU#772817</ref>
      <ref url="http://www.kb.cert.org/vuls/id/542873" source="CERT-VN">VU#542873</ref>
      <ref url="http://www.kb.cert.org/vuls/id/206361" source="CERT-VN">VU#206361</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/6871" source="BID" patch="1" adv="1">6871</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431461&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11337" source="XF" adv="1">lotus-domino-hostname-bo(11337)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11336" source="XF">lotus-domino-inotes-bo(11336)</ref>
      <ref url="http://www.securityfocus.com/bid/6870" source="BID">6870</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt" source="MISC">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt" source="MISC">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" source="NTBUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777531350&amp;w=2" source="NTBUGTRAQ">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777331345&amp;w=2" source="NTBUGTRAQ">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2" source="BUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431463&amp;w=2" source="BUGTRAQ">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" source="VULNWATCH">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html" source="VULNWATCH">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html" source="VULNWATCH">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0179" published="2003-04-02" name="CVE-2003-0179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/571297" source="CERT-VN" patch="1" adv="1">VU#571297</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT">CA-2003-11</ref>
      <ref url="http://www.securityfocus.com/bid/6872" source="BID" patch="1" adv="1">6872</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550124032513&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11339" source="XF">lotus-notes-activex-bo(11339)</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt" source="MISC">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21104543" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2" source="NTBUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778131373&amp;w=2" source="NTBUGTRAQ">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2" source="BUGTRAQ">20030217 Domino Advisories UPDATE</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html" source="VULNWATCH">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes_client">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0180" published="2003-04-02" name="CVE-2003-0180" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/355169" source="CERT-VN" patch="1" adv="1">VU#355169</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT" patch="1" adv="1">CA-2003-11</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-60dos.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11360" source="XF">lotus-incomplete-post-dos(11360)</ref>
      <ref url="http://www.securityfocus.com/bid/6951" source="BID">6951</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-065.shtml" source="CIAC">N-065</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" source="VULNWATCH">20030218 More Lotus Domino Advisories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0181" published="2003-04-02" name="CVE-2003-0181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-11.html" source="CERT" patch="1" adv="1">CA-2003-11</ref>
      <ref url="http://www.nextgenss.com/advisories/lotus-60dos.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11361" source="XF">lotus-invalid-field-dos(11361)</ref>
      <ref url="http://www.securityfocus.com/bid/6951" source="BID">6951</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html" source="VULNWATCH">20030218 More Lotus Domino Advisories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0187" published="2003-08-27" name="CVE-2003-0187" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105986028426824&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030802 [SECURITY] Netfilter Security Advisory: Conntrack list_del() DoS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:260" source="OVAL" sig="1">oval:org.mitre.oval:def:260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0188" published="2003-06-09" name="CVE-2003-0188" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-169.html" source="REDHAT" patch="1" adv="1">RHSA-2003:169</ref>
      <ref url="http://www.debian.org/security/2003/dsa-304" source="DEBIAN" patch="1" adv="1">DSA-304</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-35.txt" source="TURBO">TLSA-2003-35</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-167.html" source="REDHAT">RHSA-2003:167</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:430" source="OVAL" sig="1">oval:org.mitre.oval:def:430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lv" name="lv">
        <vers num="4.49.1"/>
        <vers num="4.49.2"/>
        <vers num="4.49.3"/>
        <vers num="4.49.4"/>
      </prod>
      <prod vendor="redhat" name="lv">
        <vers num="4.49.4-1" edition=""/>
        <vers num="4.49.4-1" edition=":i386"/>
        <vers num="4.49.4-3" edition=""/>
        <vers num="4.49.4-3" edition=":i386"/>
        <vers num="4.49.4-7" edition=""/>
        <vers num="4.49.4-7" edition=":i386"/>
        <vers num="4.49.4-9" edition=""/>
        <vers num="4.49.4-9" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0189" published="2003-06-09" name="CVE-2003-0189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <env/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/479268" source="CERT-VN">VU#479268</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-186.html" source="REDHAT" patch="1" adv="1">RHSA-2003:186</ref>
      <ref url="http://www.apache.org/dist/httpd/Announcement2.html" source="CONFIRM" patch="1" adv="1">http://www.apache.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12091" source="XF">apache-aprpasswordvalidate-dos(12091)</ref>
      <ref url="http://www.securityfocus.com/bid/7725" source="BID">7725</ref>
      <ref url="http://secunia.com/advisories/8881" source="SECUNIA">8881</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" source="CONECTIVA">CLA-2003:661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0190" published="2003-05-12" name="CVE-2003-0190" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7467" source="BID" patch="1" adv="1">7467</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-31.txt" source="TURBO">TLSA-2003-31</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-224.html" source="REDHAT">RHSA-2003:224</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-222.html" source="REDHAT">RHSA-2003:222</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018677302607&amp;w=2" source="BUGTRAQ">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html" source="FULLDISC">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref url="http://lab.mediaservice.net/advisory/2003-01-openssh.txt" source="MISC">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:445" source="OVAL" sig="1">oval:org.mitre.oval:def:445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.4p1"/>
        <vers num="3.6.1p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0192" published="2003-08-18" name="CVE-2003-0192" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-240.html" source="REDHAT" patch="1" adv="1">RHSA-2003:240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-243.html" source="REDHAT">RHSA-2003:243</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" source="SCO">SCOSA-2004.6</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-244.html" source="REDHAT">RHSA-2003:244</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" source="MANDRAKE">MDKSA-2003:075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:169" source="OVAL" sig="1">oval:org.mitre.oval:def:169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0193" published="2004-08-18" name="CVE-2003-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-575" source="DEBIAN">DSA-575</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16335" source="XF">catdoc-xlsview-symlink(16335)</ref>
      <ref url="http://www.securityfocus.com/bid/11560" source="BID">11560</ref>
      <ref url="http://www.osvdb.org/11193" source="OSVDB">11193</ref>
      <ref url="http://secunia.com/advisories/13022/" source="SECUNIA">13022</ref>
      <ref url="http://secunia.com/advisories/13021/" source="SECUNIA">13021</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="catdoc" name="catdoc">
        <vers prev="1" num="0.91"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0194" published="2003-06-09" name="CVE-2003-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">tcpdump does not properly drop privileges to the pcap user when starting up.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-174.html" source="REDHAT" patch="1" adv="1">RHSA-2003:174</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-151.html" source="REDHAT">RHSA-2003:151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="tcpdump">
        <vers num="3.4-39" edition=""/>
        <vers num="3.4-39" edition=":i386"/>
        <vers num="3.6.2-12" edition=""/>
        <vers num="3.6.2-12" edition=":i386"/>
        <vers num="3.6.2-9" edition=""/>
        <vers num="3.6.2-9" edition=":i386"/>
        <vers num="3.6.2-9" edition=":ia64"/>
        <vers num="3.6.3-3" edition=""/>
        <vers num="3.6.3-3" edition=":i386"/>
        <vers num="3.7.2-1" edition=""/>
        <vers num="3.7.2-1" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0195" published="2003-06-16" name="CVE-2003-0195" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-171.html" source="REDHAT" patch="1" adv="1">RHSA-2003:171</ref>
      <ref url="http://www.debian.org/security/2003/dsa-317" source="DEBIAN" patch="1" adv="1">DSA-317</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-33.txt" source="TURBO">TLSA-2003-33</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_028.html" source="SUSE">SuSE-SA:2003:028</ref>
      <ref url="http://www.securityfocus.com/bid/7637" source="BID">7637</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:062" source="MANDRAKE">MDKSA-2003:062</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427288724449&amp;w=2" source="BUGTRAQ">20030529 [slackware-security]  CUPS DoS vulnerability fixed (SSA:2003-149-01)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000678" source="CONECTIVA">CLSA-2003:678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6" source="OVAL" sig="1">oval:org.mitre.oval:def:6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="8.1"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0196" published="2003-05-05" name="CVE-2003-0196" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-137.html" source="REDHAT" patch="1" adv="1">RHSA-2003:137</ref>
      <ref url="http://www.debian.org/security/2003/dsa-280" source="DEBIAN" patch="1" adv="1">DSA-280</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104973186901597&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030407 [OpenPKG-SA-2003.028] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" source="MANDRAKE">MDKSA-2003:044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2" source="BUGTRAQ">20030407 Immunix Secured OS 7+ samba update</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:564" source="OVAL" sig="1">oval:org.mitre.oval:def:564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="cifs-9000_server">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
        <vers num="a.01.07"/>
        <vers num="a.01.08"/>
        <vers num="a.01.08.01"/>
        <vers num="a.01.09"/>
        <vers num="a.01.09.01"/>
        <vers num="a.01.09.02"/>
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8"/>
      </prod>
      <prod vendor="samba-tng" name="samba-tng">
        <vers num="0.3"/>
        <vers num="0.3.1"/>
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0b"/>
        <vers num="4.0d"/>
        <vers num="4.0d_pk9_bl17"/>
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="5.0"/>
        <vers num="5.0_pk4_bl17"/>
        <vers num="5.0_pk4_bl18"/>
        <vers num="5.0a"/>
        <vers num="5.0a_pk3_bl17"/>
        <vers num="5.0f"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition=""/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":x86"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0197" published="2003-04-11" name="CVE-2003-0197" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt" source="MISC" patch="1" adv="1">http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104940730819887&amp;w=2" source="BUGTRAQ">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html" source="VULNWATCH">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="interbase">
        <vers num="6.0"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0198" published="2003-05-05" name="CVE-2003-0198" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00028.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0201" published="2003-05-05" name="CVE-2003-0201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/267873" source="CERT-VN">VU#267873</ref>
      <ref url="http://www.securityfocus.com/bid/7294" source="BID" patch="1" adv="1">7294</ref>
      <ref url="http://www.debian.org/security/2003/dsa-280" source="DEBIAN" patch="1" adv="1">DSA-280</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104972664226781&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030407 [DDI-1013] Buffer Overflow in Samba allows remote root compromise</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-137.html" source="REDHAT">RHSA-2003:137</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_025_samba.html" source="SUSE">SuSE-SA:2003:025</ref>
      <ref url="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt" source="MISC">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P" source="SGI">20030403-01-P</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044" source="MANDRAKE">MDKSA-2003:044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994564212488&amp;w=2" source="BUGTRAQ">20030409 GLSA:  samba (200304-02)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104981682014565&amp;w=2" source="BUGTRAQ">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2" source="BUGTRAQ">20030407 Immunix Secured OS 7+ samba update</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624" source="CONECTIVA">CLA-2003:624</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:567" source="OVAL" sig="1">oval:org.mitre.oval:def:567</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2163" source="OVAL" sig="1">oval:org.mitre.oval:def:2163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="cifs-9000_server">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
        <vers num="a.01.07"/>
        <vers num="a.01.08"/>
        <vers num="a.01.08.01"/>
        <vers num="a.01.09"/>
        <vers num="a.01.09.01"/>
        <vers num="a.01.09.02"/>
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8"/>
      </prod>
      <prod vendor="samba-tng" name="samba-tng">
        <vers num="0.3"/>
        <vers num="0.3.1"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
      <prod vendor="compaq" name="tru64">
        <vers num="4.0b"/>
        <vers num="4.0d"/>
        <vers num="4.0d_pk9_bl17"/>
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="5.0"/>
        <vers num="5.0_pk4_bl17"/>
        <vers num="5.0_pk4_bl18"/>
        <vers num="5.0a"/>
        <vers num="5.0a_pk3_bl17"/>
        <vers num="5.0f"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition=""/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":x86"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0202" published="2004-04-15" name="CVE-2003-0202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-279" source="DEBIAN" patch="1" adv="1">DSA-279</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11734" source="XF" adv="1">metrics-tmpfile-symlink(11734)</ref>
      <ref url="http://www.securityfocus.com/bid/7293" source="BID" adv="1">7293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brian_renaud" name="metrics">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0203" published="2003-04-11" name="CVE-2003-0203" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6921" source="BID" patch="1" adv="1">6921</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11399" source="XF" adv="1">moxftp-welcome-banner-bo(11399)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-281" source="DEBIAN">DSA-281</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2" source="BUGTRAQ" adv="1">20030223 moxftp arbitrary code execution poc/advisory</ref>
      <ref url="http://www.securitytracker.com/id?1006156" source="SECTRACK">1006156</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html" source="FULLDISC">20030223 moxftp arbitrary code execution poc/advisory</ref>
      <ref url="http://secunia.com/advisories/8136" source="SECUNIA">8136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moxftp" name="moxftp">
        <vers num="2.2"/>
      </prod>
      <prod vendor="xftp" name="xftp">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0204" published="2003-05-05" name="CVE-2003-0204" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20030409-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20030409-1.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-284" source="DEBIAN" patch="1" adv="1">DSA-284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-002.html" source="REDHAT">RHSA-2003:002</ref>
      <ref url="http://www.debian.org/security/2003/dsa-296" source="DEBIAN">DSA-296</ref>
      <ref url="http://www.debian.org/security/2003/dsa-293" source="DEBIAN">DSA-293</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=56808" source="CONFIRM">http://bugs.kde.org/show_bug.cgi?id=56808</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=53343" source="CONFIRM">http://bugs.kde.org/show_bug.cgi?id=53343</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049" source="MANDRAKE">MDKSA-2003:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105034222521369&amp;w=2" source="BUGTRAQ">20030414 GLSA:  kde-2.x (200304-05.1)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105017403010459&amp;w=2" source="BUGTRAQ">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105012994719099&amp;w=2" source="BUGTRAQ">20030411 GLSA:  kde-2.x (200304-05)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001557020141&amp;w=2" source="BUGTRAQ">20030410 GLSA:  kde-3.x (200304-04)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" source="CONECTIVA">CLA-2003:747</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668" source="CONECTIVA">CLA-2003:668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3a"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5a"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0205" published="2003-05-12" name="CVE-2003-0205" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-294" source="DEBIAN" patch="1" adv="1">DSA-294</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030423 Security problems in gkrellm-newsticker</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gkrellm_newsticker" name="gkrellm_newsticker">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0206" published="2003-05-12" name="CVE-2003-0206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-294" source="DEBIAN" patch="1" adv="1">DSA-294</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030423 Security problems in gkrellm-newsticker</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gkrellm_newsticker" name="gkrellm_newsticker">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0207" published="2003-05-05" name="CVE-2003-0207" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-286" source="DEBIAN" patch="1" adv="1">DSA-286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gs-common" name="gs-common">
        <vers num="0.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0208" published="2003-05-05" name="CVE-2003-0208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securiteam.com/securitynews/5XP0B0U9PE.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/securitynews/5XP0B0U9PE.html</ref>
      <ref url="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html" source="FULLDISC">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105033712615013&amp;w=2" source="BUGTRAQ">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="flash">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0209" published="2003-05-05" name="CVE-2003-0209" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/139129" source="CERT-VN" adv="1">VU#139129</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-13.html" source="CERT">CA-2003-13</ref>
      <ref url="http://www.securityfocus.com/bid/7178" source="BID" patch="1" adv="1">7178</ref>
      <ref url="http://www.debian.org/security/2003/dsa-297" source="DEBIAN">DSA-297</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172790914107&amp;w=2" source="ENGARDE">ESA-20030430-013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2" source="BUGTRAQ">20030428 GLSA:  snort (200304-06)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111217731583&amp;w=2" source="BUGTRAQ">20030423 Snort &lt;=1.9.1 exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105103586927007&amp;w=2" source="BUGTRAQ">20030422 GLSA:  snort (200304-05)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105043563016235&amp;w=2" source="BUGTRAQ">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052" source="MANDRAKE">MDKSA-2003:052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smoothwall" name="smoothwall">
        <vers num="2.0_beta_4"/>
      </prod>
      <prod vendor="sourcefire" name="snort">
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.9"/>
        <vers num="1.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0210" published="2003-05-12" name="CVE-2003-0210" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/697049" source="CERT-VN">VU#697049</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml" source="CISCO" patch="1" adv="1">20030423 Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120066126196&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105118056332344&amp;w=2" source="NTBUGTRAQ">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.1"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.3"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0211" published="2003-05-05" name="CVE-2003-0211" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068673220605&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030418 Xinetd 2.3.10 Memory Leaks</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-160.html" source="REDHAT">RHSA-2003:160</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056" source="MANDRAKE">MDKSA-2003:056</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782" source="CONECTIVA">CLA-2003:782</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:657" source="OVAL" sig="1">oval:org.mitre.oval:def:657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xinetd" name="xinetd">
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0212" published="2003-05-12" name="CVE-2003-0212" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-289" source="DEBIAN" patch="1" adv="1">DSA-289</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105059298502830&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030417 Vulnerability in rinetd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rinetd" name="rinetd">
        <vers num="0.52"/>
        <vers num="0.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0213" published="2003-05-12" name="CVE-2003-0213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/673993" source="CERT-VN">VU#673993</ref>
      <ref url="http://www.securityfocus.com/bid/7316" source="BID" patch="1" adv="1">7316</ref>
      <ref url="http://www.securityfocus.com/archive/1/317995" source="BUGTRAQ" patch="1" adv="1">20030409 PoPToP PPTP server remotely exploitable buffer overflow</ref>
      <ref url="http://www.debian.org/security/2003/dsa-295" source="DEBIAN" patch="1" adv="1">DSA-295</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_029.html" source="SUSE">SuSE-SA:2003:029</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068728421160&amp;w=2" source="BUGTRAQ" adv="1">20030418 Exploit for PoPToP PPTP server</ref>
      <ref url="http://www.securityfocus.com/archive/1/319428" source="BUGTRAQ">20030422 Re: Exploit for PoPToP PPTP server - Linux version</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=138437" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=138437</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154539727967&amp;w=2" source="BUGTRAQ">20030428 GLSA:  pptpd (200304-08)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poptop" name="pptp_server">
        <vers num="1.0.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.3_2002-10-09"/>
        <vers num="1.1.4b1"/>
        <vers num="1.1.4b2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0214" published="2003-05-12" name="CVE-2003-0214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-292" source="DEBIAN" patch="1" adv="1">DSA-292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="mime-support">
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.17"/>
        <vers num="3.18"/>
        <vers num="3.19"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0215" published="2003-05-12" name="CVE-2003-0215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812" source="CONFIRM" patch="1" adv="1">http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120052725940&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030424 SQL injection in BttlxeForum</ref>
      <ref url="http://securitytracker.com/id?1006632" source="SECTRACK">1006632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleaxe_software" name="bttlxeforum">
        <vers prev="1" num="2.0_beta_3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0216" published="2003-05-12" name="CVE-2003-0216" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/443257" source="CERT-VN">VU#443257</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml." source="CISCO">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catos">
        <vers num="7.5(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0217" published="2003-06-16" name="CVE-2003-0217" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105283833617480&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 XSS In Neoteris IVE Allows Session Hijacking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0218" published="2003-05-12" name="CVE-2003-0218" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7202" source="BID" patch="1" adv="1">7202</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154473526898&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030428 GLSA:  monkeyd (200304-07.1)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html" source="VULNWATCH" patch="1" adv="1">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
      <ref url="http://monkeyd.sourceforge.net/Changelog.txt" source="CONFIRM">http://monkeyd.sourceforge.net/Changelog.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105094204204166&amp;w=2" source="BUGTRAQ">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey-project" name="monkey_http_daemon">
        <vers num="0.1.1"/>
        <vers num="0.5.2"/>
        <vers num="0.6.0"/>
        <vers prev="1" num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0219" published="2003-05-12" name="CVE-2003-0219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/641012" source="CERT-VN">VU#641012</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
      <ref url="http://www.securityfocus.com/bid/7179" source="BID">7179</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2" source="BUGTRAQ">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall_2">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0220" published="2003-05-12" name="CVE-2003-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/454716" source="CERT-VN">VU#454716</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
      <ref url="http://www.securityfocus.com/bid/7180" source="BID">7180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2" source="BUGTRAQ">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall_2">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0221" published="2003-05-12" name="CVE-2003-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11892" source="XF">tru64-dupatch-setld-symlink(11892)</ref>
      <ref url="http://www.securityfocus.com/bid/7452" source="BID">7452</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-086.shtml" source="HP">SSRT3471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="tru64">
        <vers prev="1" num="5.1b" edition="pk1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0222" published="2003-05-12" name="CVE-2003-0222" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7453" source="BID" patch="1" adv="1">7453</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11885" source="XF">oracle-database-link-bo(11885)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-085.shtml" source="CIAC">N-085</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105163376015735&amp;w=2" source="NTBUGTRAQ">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105162831008176&amp;w=2" source="BUGTRAQ">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.0.5.1"/>
        <vers num="8.0.6"/>
        <vers num="8.1.5"/>
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.0.6"/>
        <vers num="8.0.6.3"/>
        <vers num="8.0x"/>
        <vers num="8.1.5"/>
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
        <vers num="8.1.7.1"/>
        <vers num="8.1.7.4"/>
        <vers num="8.1x"/>
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.1.2"/>
        <vers num="9.0.1.3"/>
        <vers num="9.0.1.4"/>
        <vers num="9.0.2"/>
        <vers num="9.2.0.1"/>
        <vers num="9.2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0223" published="2003-06-09" name="CVE-2003-0223" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:66" source="OVAL" sig="1">oval:org.mitre.oval:def:66</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0224" published="2003-06-09" name="CVE-2003-0224" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105431767100944&amp;w=2" source="NTBUGTRAQ">20030530 NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:483" source="OVAL" sig="1">oval:org.mitre.oval:def:483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0225" published="2003-06-09" name="CVE-2003-0225" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://www.aqtronix.com/Advisories/AQ-2003-01.txt" source="MISC">http://www.aqtronix.com/Advisories/AQ-2003-01.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105110606122772&amp;w=2" source="NTBUGTRAQ">20030418 Microsoft Active Server Pages DoS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:373" source="OVAL" sig="1">oval:org.mitre.oval:def:373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0226" published="2003-06-09" name="CVE-2003-0226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.spidynamics.com/iis_alert.html" source="MISC" patch="1" adv="1">http://www.spidynamics.com/iis_alert.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-018.asp" source="MS" patch="1" adv="1">MS03-018</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0308.html" source="BUGTRAQ" patch="1" adv="1">20030528 Internet Information Services 5.0 Denial of service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421243732552&amp;w=2" source="NTBUGTRAQ">20030528 Internet Information Services 5.0 Denial of service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427362724860&amp;w=2" source="BUGTRAQ">20030529 IIS WEBDAV Denial of Service attacks</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:933" source="OVAL" sig="1">oval:org.mitre.oval:def:933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0227" published="2003-06-09" name="CVE-2003-0227" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-019.asp" source="MS" patch="1" adv="1">MS03-019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421176432011&amp;w=2" source="NTBUGTRAQ">20030528 MS03-019: DoS or Code of Choice</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105421127531558&amp;w=2" source="NTBUGTRAQ">20030528 Re: Alert: MS03-019, Microsoft... wrong, again.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427615626177&amp;w=2" source="BUGTRAQ">20030528 RE: Alert: MS03-019, Microsoft... wrong, again.</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:966" source="OVAL" sig="1">oval:org.mitre.oval:def:966</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:936" source="OVAL" sig="1">oval:org.mitre.oval:def:936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0228" published="2003-05-27" name="CVE-2003-0228" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/384932" source="CERT-VN">VU#384932</ref>
      <ref url="http://www.securityfocus.com/bid/7517" source="BID" patch="1" adv="1">7517</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-017.asp" source="MS" patch="1" adv="1">MS03-017</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232913516488&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030507 Windows Media Player directory traversal vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11953" source="XF">mediaplayer-skin-code-execution(11953)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233960728901&amp;w=2" source="NTBUGTRAQ">20030507 Windows Media Player directory traversal vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240528419389&amp;w=2" source="BUGTRAQ">20030508 why i love xs4all + mediaplayer thingie</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:321" source="OVAL" sig="1">oval:org.mitre.oval:def:321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="7.1"/>
        <vers num="xp"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0230" published="2003-08-27" name="CVE-2003-0230" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/556356" source="CERT-VN">VU#556356</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp" source="MS" patch="1">MS03-031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:235" source="OVAL" sig="1">oval:org.mitre.oval:def:235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition=""/>
        <vers num="2000" edition=":desktop_engine"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sp3a"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0231" published="2003-08-27" name="CVE-2003-0231" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/918652" source="CERT-VN">VU#918652</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp" source="MS">MS03-031</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a072303-2.txt" source="ATSTAKE">A072303-2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:299" source="OVAL" sig="1">oval:org.mitre.oval:def:299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition=""/>
        <vers num="2000" edition=":desktop_engine"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sp3a"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0232" published="2003-08-27" name="CVE-2003-0232" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/584868" source="CERT-VN">VU#584868</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-031.asp" source="MS" patch="1" adv="1">MS03-031</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a072303-3.txt" source="ATSTAKE" patch="1" adv="1">A072303-3</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:303" source="OVAL" sig="1">oval:org.mitre.oval:def:303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition=""/>
        <vers num="2000" edition=":desktop_engine"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sp3a"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0233" published="2003-05-12" name="CVE-2003-0233" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" source="MS" patch="1" adv="1">MS03-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120164927952&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030424 Internet Explorer Plugin.ocx heap overflow (#NISR24042003)</ref>
      <ref url="http://www.iss.net/security_center/static/11854.php" source="XF" adv="1">ie-plugin-load-bo(11854)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1094" source="OVAL" sig="1">oval:org.mitre.oval:def:1094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0235" published="2003-05-27" name="CVE-2003-0235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7461" source="BID" adv="1">7461</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11938" source="XF">icq-pop3-format-string(11938)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0236" published="2003-05-27" name="CVE-2003-0236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7463" source="BID" adv="1">7463</ref>
      <ref url="http://www.securityfocus.com/bid/7462" source="BID" adv="1">7462</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11939" source="XF">icq-pop3-email-bo(11939)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0237" published="2003-05-27" name="CVE-2003-0237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7464" source="BID" patch="1" adv="1">7464</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11944" source="XF">icq-features-no-auth(11944)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0238" published="2003-05-27" name="CVE-2003-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7465" source="BID" adv="1">7465</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11947" source="XF">icq-table-tag-dos(11947)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0239" published="2003-05-27" name="CVE-2003-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7466" source="BID" adv="1">7466</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" source="MISC" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html" source="VULNWATCH">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11948" source="XF">icq-gif89a-header-dos(11948)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216842131995&amp;w=2" source="BUGTRAQ">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0240" published="2003-06-09" name="CVE-2003-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/799060" source="CERT-VN">VU#799060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12104" source="XF">axis-admin-authentication-bypass(12104)</ref>
      <ref url="http://www.securityfocus.com/bid/7652" source="BID">7652</ref>
      <ref url="http://securitytracker.com/id?1006854" source="SECTRACK">1006854</ref>
      <ref url="http://secunia.com/advisories/8876" source="SECUNIA">8876</ref>
      <ref url="http://www.osvdb.org/4804" source="OSVDB">4804</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406374731579&amp;w=2" source="BUGTRAQ">20030527 CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axis" name="2100_network_camera">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2110_network_camera">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2120_network_camera">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2130_ptz_network_camera">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2400_video_server">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2401_video_server">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2420_network_camera">
        <vers prev="1" num="2.32"/>
      </prod>
      <prod vendor="axis" name="2460_network_dvr">
        <vers prev="1" num="3.00"/>
      </prod>
      <prod vendor="axis" name="250s_video_server">
        <vers prev="1" num="3.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0241" published="2003-06-09" name="CVE-2003-0241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.secnap.net/security/gm001.html" source="MISC" patch="1" adv="1">http://www.secnap.net/security/gm001.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0091.html" source="VULNWATCH" patch="1" adv="1">20030528 SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frontrange" name="goldmine">
        <vers num="5.70"/>
        <vers num="6.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0242" published="2003-06-09" name="CVE-2003-0242" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/869548" source="CERT-VN">VU#869548</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12027" source="XF">macos-ipsec-acl-bypass(12027)</ref>
      <ref url="http://www.securityfocus.com/bid/7628" source="BID">7628</ref>
      <ref url="http://securitytracker.com/id?1006796" source="SECTRACK">1006796</ref>
      <ref url="http://secunia.com/advisories/8798" source="SECUNIA">8798</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0243" published="2003-05-27" name="CVE-2003-0243" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1006707" source="SECTRACK">1006707</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0058.html" source="VULNWATCH">20030507 Happymall E-Commerce Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="happycgi" name="happymall">
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0244" published="2003-05-27" name="CVE-2003-0244" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-145.html" source="REDHAT" patch="1" adv="1">RHSA-2003:145</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-172.html" source="REDHAT">RHSA-2003:172</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-147.html" source="REDHAT">RHSA-2003:147</ref>
      <ref url="http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html" source="MISC">http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105595901923063&amp;w=2" source="BUGTRAQ">20030618 [slackware-security]  2.4.21 kernels available (SSA:2003-168-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" source="ENGARDE">ESA-20030515-017</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0073.html" source="VULNWATCH">20030517 Algorithmic Complexity Attacks and the Linux Networking Code</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15382" source="XF">data-algorithmic-complexity-dos(15382)</ref>
      <ref url="http://www.securityfocus.com/bid/7601" source="BID">7601</ref>
      <ref url="http://www.secunia.com/advisories/8786/" source="SECUNIA">8786</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=104956079213417" source="MISC">http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=104956079213417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:261" source="OVAL" sig="1">oval:org.mitre.oval:def:261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0245" published="2003-06-09" name="CVE-2003-0245" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757612" source="CERT-VN" adv="1">VU#757612</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-186.html" source="REDHAT" patch="1" adv="1">RHSA-2003:186</ref>
      <ref url="http://www.apache.org/dist/httpd/Announcement2.html" source="CONFIRM" patch="1" adv="1">http://www.apache.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12090" source="XF">apache-aprpsprintf-code-execution(12090)</ref>
      <ref url="http://www.securityfocus.com/bid/7723" source="BID">7723</ref>
      <ref url="http://www.idefense.com/advisory/05.30.03.txt" source="MISC">http://www.idefense.com/advisory/05.30.03.txt </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html" source="VULNWATCH">20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:063" source="MANDRAKE">MDKSA-2003:063</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661" source="CONECTIVA">CLA-2003:661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0246" published="2003-06-16" name="CVE-2003-0246" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-172.html" source="REDHAT" patch="1" adv="1">RHSA-2003:172</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2" source="ENGARDE" patch="1" adv="1">ESA-20030515-017</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-147.html" source="REDHAT">RHSA-2003:147</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html" source="VULNWATCH">20030520 Linux 2.4 kernel ioperm vuln</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:278" source="OVAL" sig="1">oval:org.mitre.oval:def:278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0247" published="2003-06-16" name="CVE-2003-0247" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-187.html" source="REDHAT" patch="1" adv="1">RHSA-2003:187</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-195.html" source="REDHAT">RHSA-2003:195</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:284" source="OVAL" sig="1">oval:org.mitre.oval:def:284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0248" published="2003-06-16" name="CVE-2003-0248" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-187.html" source="REDHAT" patch="1" adv="1">RHSA-2003:187</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-195.html" source="REDHAT">RHSA-2003:195</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066" source="MANDRAKE">MDKSA-2003:066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:292" source="OVAL" sig="1">oval:org.mitre.oval:def:292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0249" published="2003-12-31" name="CVE-2003-0249" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive.  NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method.  A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods.  It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=97" source="IDEFENSE" adv="1">20030625 PHP/Apache .htaccess Authentication Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0251" published="2003-07-24" name="CVE-2003-0251" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-173.html" source="REDHAT" patch="1" adv="1">RHSA-2003:173</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2873" source="VUPEN">ADV-2006-2873</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-43.txt" source="TURBO">TLSA-2003-43</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440454/100/0/threaded" source="HP">SSRT061154</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55600&amp;zone_32=category%3Asecurity" source="SUNALERT">55600</ref>
      <ref url="http://www.securityfocus.com/bid/8031" source="BID">8031</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/440454/100/0/threaded" source="HP">HPSBTU02132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-201.html" source="REDHAT">RHSA-2003:201</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:072" source="MANDRAKE">MDKSA-2003:072</ref>
      <ref url="http://securitytracker.com/id?1016517" source="SECTRACK">1016517</ref>
      <ref url="http://secunia.com/advisories/21112" source="SECUNIA">21112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:667" source="OVAL" sig="1">oval:org.mitre.oval:def:667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nis" name="ypserv_nis_server">
        <vers prev="1" num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0252" published="2003-08-18" name="CVE-2003-0252" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/258564" source="CERT-VN">VU#258564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830921519513&amp;w=2" source="BUGTRAQ" patch="1">20030715 [slackware-security]  nfs-utils packages replaced (SSA:2003-195-01b)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12600" source="XF">nfs-utils-offbyone-bo(12600)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-44.txt" source="TURBO">TLSA-2003-44</ref>
      <ref url="http://www.securityfocus.com/bid/8179" source="BID">8179</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-207.html" source="REDHAT">RHSA-2003:207</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-206.html" source="REDHAT">RHSA-2003:206</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_031_nfs_utils.html" source="SUSE">SuSE-SA:2003:031</ref>
      <ref url="http://www.debian.org/security/2003/dsa-349" source="DEBIAN">DSA-349</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001262.1-1" source="SUNALERT">1001262</ref>
      <ref url="http://securitytracker.com/id?1007187" source="SECTRACK">1007187</ref>
      <ref url="http://secunia.com/advisories/9259" source="SECUNIA">9259</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839032403325&amp;w=2" source="BUGTRAQ" adv="1">20030716 Immunix Secured OS 7+ nfs-utils update -- bugtraq</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820223707191&amp;w=2" source="BUGTRAQ" adv="1">20030714 Linux nfs-utils xlog() off-by-one bug</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html" source="VULNWATCH" adv="1">20030714 Reality of the rpc.mountd bug</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html" source="VULNWATCH" adv="1">20030714 Linux nfs-utils xlog() off-by-one bug</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:076" source="MANDRAKE">MDKSA-2003:076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:443" source="OVAL" sig="1">oval:org.mitre.oval:def:443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3.1"/>
        <vers num="0.3.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0253" published="2003-08-18" name="CVE-2003-0253" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-240.html" source="REDHAT" patch="1" adv="1">RHSA-2003:240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" source="MANDRAKE">MDKSA-2003:075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:173" source="OVAL" sig="1">oval:org.mitre.oval:def:173</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0254" published="2003-08-18" name="CVE-2003-0254" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-240.html" source="REDHAT" patch="1" adv="1">RHSA-2003:240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105776593602600&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075" source="MANDRAKE">MDKSA-2003:075</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:183" source="OVAL" sig="1">oval:org.mitre.oval:def:183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0255" published="2003-05-27" name="CVE-2003-0255" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/397604" source="CERT-VN">VU#397604</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-175.html" source="REDHAT" patch="1" adv="1">RHSA-2003:175</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105215110111174&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030504 Key validity bug in GnuPG 1.2.1 and earlier</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11930" source="XF">gnupg-invalid-key-acceptance(11930)</ref>
      <ref url="http://www.securityfocus.com/bid/7497" source="BID">7497</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-176.html" source="REDHAT">RHSA-2003:176</ref>
      <ref url="http://www.osvdb.org/4947" source="OSVDB">4947</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-34.txt" source="TURBO">TLSA200334</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:061" source="MANDRAKE">MDKSA-2003:061</ref>
      <ref url="http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html" source="MISC">http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html" source="ENGARDE">20030515-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362224514081&amp;w=2" source="BUGTRAQ">20030522 [slackware-security]  GnuPG key validation fix (SSA:2003-141-04)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311804129104&amp;w=2" source="BUGTRAQ">20030516 [OpenPKG-SA-2003.029] OpenPKG Security Advisory (gnupg)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301357425157&amp;w=2" source="ENGARDE">ESA-20030515-016</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000694" source="CONECTIVA">CLA-2003:694</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:135" source="OVAL" sig="1">oval:org.mitre.oval:def:135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0256" published="2003-05-27" name="CVE-2003-0256" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:055" source="MANDRAKE">MDKSA-2003:055</ref>
      <ref url="http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2" source="CONFIRM">http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000665" source="CONECTIVA">CLA-2003:665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kopete">
        <vers num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0257" published="2004-04-15" name="CVE-2003-0257" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1" source="IBM" patch="1" adv="1">MSS-OAR-E01-2003:0660.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12000" source="XF" adv="1">aix-print-format-string(12000)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0258" published="2003-05-27" name="CVE-2003-0258" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/727780" source="CERT-VN">VU#727780</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" source="CISCO" patch="1" adv="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11954" source="XF">cisco-vpn-unauth-access(11954)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="3.5(rel)"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.7d"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3"/>
        <vers num="3.6.5"/>
        <vers num="3.6.7"/>
        <vers num="3.6.7.a"/>
        <vers num="3.6.7.b"/>
        <vers num="3.6.7.c"/>
        <vers num="3.6.7.d"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0259" published="2003-05-27" name="CVE-2003-0259" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/317348" source="CERT-VN">VU#317348</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" source="CISCO" patch="1" adv="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11955" source="XF">cisco-vpn-ssh-dos(11955)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.0"/>
        <vers num="2.5.2.a"/>
        <vers num="2.5.2.b"/>
        <vers num="2.5.2.c"/>
        <vers num="2.5.2.d"/>
        <vers num="2.5.2.f"/>
        <vers num="3.0"/>
        <vers num="3.0.3.a"/>
        <vers num="3.0.3.b"/>
        <vers num="3.0.4"/>
        <vers num="3.1"/>
        <vers num="3.1(rel)"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.4"/>
        <vers num="3.5(rel)"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.7"/>
        <vers num="3.6.7d"/>
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3"/>
        <vers num="3.6.5"/>
        <vers num="3.6.7"/>
        <vers num="3.6.7.a"/>
        <vers num="3.6.7.b"/>
        <vers num="3.6.7.c"/>
        <vers num="3.6.7.d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0260" published="2003-05-27" name="CVE-2003-0260" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/221164" source="CERT-VN">VU#221164</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" source="CISCO" patch="1" adv="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11956" source="XF">cisco-vpn-icmp-dos(11956)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3002_hardware_client">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.0"/>
        <vers num="2.5.2.a"/>
        <vers num="2.5.2.b"/>
        <vers num="2.5.2.c"/>
        <vers num="2.5.2.d"/>
        <vers num="2.5.2.f"/>
        <vers num="3.0"/>
        <vers num="3.0.3.a"/>
        <vers num="3.0.3.b"/>
        <vers num="3.0.4"/>
        <vers num="3.1"/>
        <vers num="3.1(rel)"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.4"/>
        <vers num="3.5(rel)"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.7"/>
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="3.6.3"/>
        <vers num="3.6.5"/>
        <vers num="3.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0261" published="2003-05-27" name="CVE-2003-0261" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-302" source="DEBIAN" patch="1" adv="1">DSA-302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuzz" name="fuzz">
        <vers prev="1" num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0262" published="2003-05-27" name="CVE-2003-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-299" source="DEBIAN" patch="1" adv="1">DSA-299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11945" source="XF">kataxwr-gain-privileges(11945)</ref>
      <ref url="http://www.securityfocus.com/bid/7505" source="BID">7505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leksbot" name="leksbot">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0263" published="2003-05-27" name="CVE-2003-0263" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7508" source="BID" patch="1" adv="1">7508</ref>
      <ref url="http://www.securityfocus.com/bid/7506" source="BID" patch="1" adv="1">7506</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105223471822836&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11951" source="XF">ftgate-mailfrom-rcptto-bo(11951)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0052.html" source="VULNWATCH">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="floosietek" name="ftgatepro">
        <vers num="1.22_1328"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0264" published="2003-05-27" name="CVE-2003-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slmail-vulns.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/slmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233360321895&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232506011335&amp;w=2" source="BUGTRAQ">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail">
        <vers num="5.1.0.4420"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0265" published="2003-05-27" name="CVE-2003-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7421" source="BID" patch="1" adv="1">7421</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232424810097&amp;w=2" source="BUGTRAQ">20030507 SAP database local root vulnerability during installation. (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_db">
        <vers num="7.3.29"/>
        <vers num="7.4.3.7_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0266" published="2003-05-27" name="CVE-2003-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" source="MISC" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2" source="BUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bvrp_software" name="slwebmail">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0267" published="2003-05-27" name="CVE-2003-0267" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" source="MISC" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2" source="BUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bvrp_software" name="slwebmail">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0268" published="2003-05-27" name="CVE-2003-0268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" source="MISC" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105233363721919&amp;w=2" source="NTBUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105232436210273&amp;w=2" source="BUGTRAQ">20030507 Multiple Vulnerabilities in SLWebmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bvrp_software" name="slwebmail">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0269" published="2003-05-27" name="CVE-2003-0269" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7503" source="BID" adv="1">7503</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004892.html" source="FULLDISC">20030506 youbin local root exploit + advisory</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0053.html" source="VULNWATCH">20030506 youbin local root exploit + advisory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11949" source="XF">youbin-home-bo(11949)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105223947528794&amp;w=2" source="BUGTRAQ">20030506 youbin local root exploit + advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youbin" name="youbin">
        <vers num="2.5"/>
        <vers num="3.0"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0270" published="2003-06-16" name="CVE-2003-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11980" source="XF">airport-auth-credentials-disclosure(11980)</ref>
      <ref url="http://www.securityfocus.com/bid/7554" source="BID" adv="1">7554</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a051203-1.txt" source="ATSTAKE" adv="1">A051203-1</ref>
      <ref url="http://securitytracker.com/id?1006742" source="SECTRACK">1006742</ref>
      <ref url="http://secunia.com/advisories/8773" source="SECUNIA">8773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="802.11n">
        <vers num="7.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0271" published="2003-05-27" name="CVE-2003-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/316958" source="BUGTRAQ" adv="1">20030331 Personal FTP Server</ref>
      <ref url="http://security.nnov.ru/search/document.asp?docid=4309" source="MISC">http://security.nnov.ru/search/document.asp?docid=4309</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240469318622&amp;w=2" source="BUGTRAQ" adv="1">20030508 Remote Stack Overflow exploit for Personal FTPD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cooolsoft" name="personal_ftp_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0272" published="2003-05-27" name="CVE-2003-0272" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240907024660&amp;w=2" source="BUGTRAQ" patch="1">20030508 miniPortail (PHP) : Admin Access</ref>
      <ref url="http://www.frog-man.org/tutos/miniPortail.txt" source="MISC">http://www.frog-man.org/tutos/miniPortail.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miniportal" name="miniportal">
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0273" published="2003-05-27" name="CVE-2003-0273" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html" source="CONFIRM" adv="1">http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105240947225275&amp;w=2" source="BUGTRAQ">20030508 Fw: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_practical_solutions" name="request_tracker">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0274" published="2003-05-27" name="CVE-2003-0274" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105241224228693&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030508 SRT2003-05-08-1137 - ListProc mailing list ULISTPROC_UMASK overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cren" name="listproc">
        <vers num="8.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0275" published="2003-06-16" name="CVE-2003-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105249980809988&amp;w=2" source="BUGTRAQ">20030509 II-Labs Advisory: Remote code execution in YaBBse 1.5.2 (php version)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.2" edition=""/>
        <vers num="1.5.2" edition=":second_edition"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0276" published="2003-06-16" name="CVE-2003-0276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11889" source="XF">pi3web-get-request-bo(11889)</ref>
      <ref url="http://www.securityfocus.com/bid/7555" source="BID">7555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105275789410250&amp;w=2" source="BUGTRAQ">20030512 Unix Version of the Pi3web DoS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155818012718&amp;w=2" source="BUGTRAQ">20030428 Pi3Web 2.0.1 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pi3" name="pi3web">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0277" published="2003-06-16" name="CVE-2003-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11987" source="XF">happymall-dotdot-directory-traversal(11987)</ref>
      <ref url="http://www.securityfocus.com/bid/7559" source="BID">7559</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276130814262&amp;w=2" source="BUGTRAQ">20030512 One more flaw in Happymall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="happycgi" name="happymall">
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0278" published="2003-06-16" name="CVE-2003-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276130814262&amp;w=2" source="BUGTRAQ">20030512 One more flaw in Happymall</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11988" source="XF">happymall-normalhtml-xss(11988)</ref>
      <ref url="http://www.securityfocus.com/bid/7557" source="BID">7557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="happycgi.com" name="happymall">
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0279" published="2003-06-16" name="CVE-2003-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11984" source="XF">phpnuke-web-sql-injection(11984)</ref>
      <ref url="http://www.securityfocus.com/bid/7558" source="BID">7558</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276019312980&amp;w=2" source="BUGTRAQ" adv="1">20030512 Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</ref>
      <ref url="http://www.securityfocus.com/bid/7588" source="BID">7588</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html" source="BUGTRAQ">20030513 More and More SQL injection on PHP-Nuke 6.5.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0280" published="2003-06-16" name="CVE-2003-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105258772101349&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11975" source="XF">cmailserver-smtp-bo(11975)</ref>
      <ref url="http://www.securityfocus.com/bid/7548" source="BID">7548</ref>
      <ref url="http://www.securityfocus.com/bid/7547" source="BID">7547</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html" source="VULNWATCH">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youngzsoft" name="cmailserver">
        <vers num="4.0.2003.23.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0281" published="2003-06-16" name="CVE-2003-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11977" source="XF">firebird-interbase-bo(11977)</ref>
      <ref url="http://www.securityfocus.com/bid/7546" source="BID">7546</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-18.xml" source="GENTOO">GLSA-200405-18</ref>
      <ref url="http://secunia.com/advisories/8758" source="SECUNIA">8758</ref>
      <ref url="http://seclists.org/lists/bugtraq/2002/Jun/0212.html" source="BUGTRAQ">20020617 Interbase 6.0 malloc() issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259012802997&amp;w=2" source="BUGTRAQ" adv="1">20030509 Firebird Local exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0282" published="2003-06-16" name="CVE-2003-0282" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7550" source="BID" patch="1" adv="1">7550</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-199.html" source="REDHAT" patch="1" adv="1">RHSA-2003:199</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-42.txt" source="TURBO">TLSA-2003-42</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-200.html" source="REDHAT">RHSA-2003:200</ref>
      <ref url="http://www.debian.org/security/2003/dsa-344" source="DEBIAN">DSA-344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259038503175&amp;w=2" source="BUGTRAQ" adv="1">20030509 unzip directory traversal revisited</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01" source="IMMUNIX">IMNX-2003-7+-017-01</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt" source="SCO">CSSA-2003-031.0</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt" source="CALDERA">CSSA-2003-031.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12004" source="XF">unzip-dotdot-directory-traversal(12004)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:073" source="MANDRAKE">MDKSA-2003:073</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-111.shtml" source="CIAC">N-111</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105786446329347&amp;w=2" source="BUGTRAQ">20030710 [OpenPKG-SA-2003.033] OpenPKG Security Advisory (infozip)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000672" source="CONECTIVA">CLA-2003:672</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:619" source="OVAL" sig="1">oval:org.mitre.oval:def:619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info-zip" name="unzip">
        <vers num="5.50"/>
      </prod>
      <prod vendor="sco" name="openlinux_server">
        <vers num="3.1.1"/>
      </prod>
      <prod vendor="sco" name="openlinux_workstation">
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0283" published="2003-06-16" name="CVE-2003-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "&lt;&lt;" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/11974" source="XF">phorum-message-html-injection(11974)</ref>
      <ref url="http://www.securityfocus.com/bid/7545" source="BID">7545</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105251421925394&amp;w=2" source="BUGTRAQ">20030509 Re: A Phorum's bug...</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105251043821533&amp;w=2" source="BUGTRAQ">20030509 A Phorum's bug...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0284" published="2003-06-16" name="CVE-2003-0284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/184820" source="CERT-VN" patch="1" adv="1">VU#184820</ref>
      <ref url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0285" published="2003-06-16" name="CVE-2003-0285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/814617" source="CERT-VN">VU#814617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11993" source="XF">aix-sendmail-mail-relay(11993)</ref>
      <ref url="http://www.securityfocus.com/bid/7580" source="BID">7580</ref>
      <ref url="http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt" source="MISC" adv="1">http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284689228961&amp;w=2" source="BUGTRAQ" adv="1">20030513 AIX sendmail open relay</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers prev="1" num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0286" published="2003-06-16" name="CVE-2003-0286" modified="2009-07-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7549" source="BID" patch="1">7549</ref>
      <ref url="http://www.securityfocus.com/bid/35764" source="BID" patch="1">35764</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11981" source="XF">snitz-register-sql-injection(11981)</ref>
      <ref url="http://secunia.com/advisories/35733" source="SECUNIA" adv="1">35733</ref>
      <ref url="http://packetstormsecurity.org/0305-exploits/snitz_exec.txt" source="MISC">http://packetstormsecurity.org/0305-exploits/snitz_exec.txt</ref>
      <ref url="http://osvdb.org/56166" source="OSVDB">56166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105277599131134&amp;w=2" source="BUGTRAQ">20030513 Snitz Forum 3.3.03 Remote Command Execution</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html" source="VULNWATCH">20030512 Snitz Forum 3.3.03 Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers prev="1" num="3.3.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0287" published="2003-06-16" name="CVE-2003-0287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <exception/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105277690132079&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030512 Re: CSS found in Movable Type</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105276879622636&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030512 CSS found in Movable Type</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284589927655&amp;w=2" source="BUGTRAQ" adv="1">20030513 Re: CSS found in Movable Type -- Nope</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12003" source="XF">movable-type-comment-xss(12003)</ref>
      <ref url="http://www.securityfocus.com/bid/7560" source="BID">7560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="six_apart" name="movable_type">
        <vers prev="1" num="2.6"/>
        <vers num="2.63"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0288" published="2003-06-16" name="CVE-2003-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the file &amp; folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/64_e.html" source="MISC" patch="1" adv="1">http://www.lac.co.jp/security/english/snsadv_e/64_e.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105283843417610&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 [SNS Advisory No.64] IP Messenger for Win Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11986" source="XF">ip-messenger-filename-bo(11986)</ref>
      <ref url="http://www.securityfocus.com/bid/7566" source="BID">7566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hiroaki_shirouzu" name="ip_messenger">
        <vers num="2.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0289" published="2003-06-16" name="CVE-2003-0289" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7565" source="BID" patch="1" adv="1">7565</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105285564307225&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 cdrtools2.0 Format String Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105286031812533&amp;w=2" source="BUGTRAQ">20030513 Cdrecord_local_root_exploit.</ref>
      <ref url="ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz" source="CONFIRM">ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12007" source="XF">cdrtools-scsiopen-format-string(12007)</ref>
      <ref url="http://www.securiteam.com/exploits/5ZP0C2AAAC.html" source="MISC">http://www.securiteam.com/exploits/5ZP0C2AAAC.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:058" source="MANDRAKE">MDKSA-2003:058</ref>
      <ref url="http://forums.gentoo.org/viewtopic.php?t=54904" source="GENTOO">200305-06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdrtools" name="cdrecord">
        <vers num="1.11"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0290" published="2003-06-16" name="CVE-2003-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284631428187&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030513 eServ Memory Leak Solution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284630228137&amp;w=2" source="BUGTRAQ" adv="1">20030511 eServ Memory Leak Enables Denial of Service Attacks</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11973" source="XF">eserv-multiple-connections-dos(11973)</ref>
      <ref url="http://www.securityfocus.com/bid/7552" source="BID">7552</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0064.html" source="VULNWATCH">20030511 eServ Memory Leak Enables Denial of Service Attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etype" name="eserv">
        <vers num="2.9x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0291" published="2003-06-16" name="CVE-2003-0291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm" source="MISC" patch="1" adv="1">http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105292451702516&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030514 Memory leak in 3COM 812 DSL routers</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301488426951&amp;w=2" source="BUGTRAQ" adv="1">20030515 RE : Memory leak in 3COM DSL routers</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11999" source="XF">3com-officeconnect-memory-leak(11999)</ref>
      <ref url="http://www.securityfocus.com/bid/7592" source="BID">7592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cp4144">
        <vers num="1.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0292" published="2003-06-16" name="CVE-2003-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7596" source="BID">7596</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105292750807005&amp;w=2" source="BUGTRAQ">20030514 Inktomi Traffic-Server XSS: man-in-the-middle XSS !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inktomi" name="inktomi_traffic-server">
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0293" published="2003-06-16" name="CVE-2003-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105293128612131&amp;w=2" source="BUGTRAQ" adv="1">20030514 PalmOS ICMP flood DoS.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palm" name="palmos">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0294" published="2003-06-16" name="CVE-2003-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105293834421549&amp;w=2" source="BUGTRAQ">20030514 php-proxima Remote File Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-proxima" name="php-proxima">
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0295" published="2003-06-16" name="CVE-2003-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105292832607981&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030514 VBulletin Preview Message - XSS Vuln</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105293890422210&amp;w=2" source="BUGTRAQ" adv="1">20030514 Re: VBulletin Preview Message - XSS Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.0_beta_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0296" published="2003-06-16" name="CVE-2003-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ximian" name="evolution">
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0297" published="2003-06-16" name="CVE-2003-0297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-114.html" source="REDHAT">RHSA-2005:114</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-015.html" source="REDHAT">RHSA-2005:015</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430302/100/0/threaded" source="FEDORA">FLSA:184074</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="c-client">
        <vers num=""/>
      </prod>
      <prod vendor="university_of_washington" name="imap-2002b">
        <vers num=""/>
      </prod>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0298" published="2003-06-16" name="CVE-2003-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3"/>
        <vers num="1.4" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0299" published="2003-06-16" name="CVE-2003-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.4.1"/>
      </prod>
      <prod vendor="stuart_parmenter" name="balsa">
        <vers num="2.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0300" published="2003-06-16" name="CVE-2003-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.00.2800.1106"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3"/>
        <vers num="1.4" edition="alpha"/>
      </prod>
      <prod vendor="mutt" name="mutt">
        <vers num="1.4.1"/>
      </prod>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1"/>
      </prod>
      <prod vendor="stuart_parmenter" name="balsa">
        <vers num="2.0.10"/>
      </prod>
      <prod vendor="sylpheed" name="sylpheed_email_client">
        <vers num="0.8.11"/>
      </prod>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.53"/>
      </prod>
      <prod vendor="ximian" name="evolution">
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0301" published="2003-06-16" name="CVE-2003-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.00.2800.1106"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0302" published="2003-06-16" name="CVE-2003-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294024124163&amp;w=2" source="BUGTRAQ" adv="1">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0303" published="2003-06-09" name="CVE-2003-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105302025601231&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" source="VULNWATCH" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref url="http://www.securityfocus.com/bid/7609" source="BID">7609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneorzero" name="oneorzero_helpdesk">
        <vers num="1.4_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0304" published="2003-06-09" name="CVE-2003-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105302025601231&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" source="VULNWATCH" patch="1" adv="1">20030515 OneOrZero Security Problems (PHP)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneorzero" name="oneorzero_helpdesk">
        <vers num="1.4_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0305" published="2003-06-09" name="CVE-2003-0305" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030515-saa.shtml" source="CISCO" patch="1" adv="1">20030515 Cisco Security Advisory: Cisco IOS Software Processing of SAA Packets</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5608" source="OVAL">oval:org.mitre.oval:def:5608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(15)s"/>
        <vers num="12.0(15)sc"/>
        <vers num="12.0(15)sl"/>
        <vers num="12.0(16)s"/>
        <vers num="12.0(16)sc"/>
        <vers num="12.0(16)st"/>
        <vers num="12.0(17)s"/>
        <vers num="12.0(17)sl"/>
        <vers num="12.0(18)s"/>
        <vers num="12.0(18)sl"/>
        <vers num="12.0(19)s"/>
        <vers num="12.0(19)sl"/>
        <vers num="12.0(19)sp"/>
        <vers num="12.0(20)sl"/>
        <vers num="12.0(20)sp"/>
        <vers num="12.0(21)s"/>
        <vers num="12.0(21)sl"/>
        <vers num="12.0(21)sx"/>
        <vers num="12.1(10)"/>
        <vers num="12.1(10)e"/>
        <vers num="12.1(10)ec"/>
        <vers num="12.1(10)ex"/>
        <vers num="12.1(10)ey"/>
        <vers num="12.1(10.5)ec"/>
        <vers num="12.1(10a)"/>
        <vers num="12.1(11)"/>
        <vers num="12.1(11.5)e"/>
        <vers num="12.1(11a)"/>
        <vers num="12.1(11b)"/>
        <vers num="12.1(11b)e"/>
        <vers num="12.1(12)"/>
        <vers num="12.1(12a)"/>
        <vers num="12.1(12b)"/>
        <vers num="12.1(12c)"/>
        <vers num="12.1(13)"/>
        <vers num="12.1(14)"/>
        <vers num="12.1(14.5)"/>
        <vers num="12.1(8)ea"/>
        <vers num="12.1(9)ea"/>
        <vers num="12.2(10.5)s"/>
        <vers num="12.2(6.8a)"/>
        <vers num="12.2(7)"/>
        <vers num="12.2(7)da"/>
        <vers num="12.2(7a)"/>
        <vers num="12.2(7b)"/>
        <vers num="12.2(7c)"/>
        <vers num="12.2(9)s"/>
        <vers num="12.2(9.4)da"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0306" published="2003-06-09" name="CVE-2003-0306" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-027.asp" source="MS">MS03-027</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=105241032526289&amp;w=2" source="VULN-DEV" adv="1">20030507 Buffer overflow in Explorer.exe</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301349925036&amp;w=2" source="BUGTRAQ" adv="1">20030515 Re[2]: EXPLOIT: Buffer overflow in Explorer.exe on Windows XP SP1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105284486526310&amp;w=2" source="BUGTRAQ" adv="1">20030511 Detailed analysis: Buffer overflow in Explorer.exe on Windows XP SP1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3095" source="OVAL" sig="1">oval:org.mitre.oval:def:3095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0307" published="2003-06-09" name="CVE-2003-0307" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105295155004969&amp;w=2" source="BUGTRAQ" adv="1">20030514 [VULNERABILITY] PHP 'poster version.two'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poster" name="poster">
        <vers num="version.two"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0308" published="2003-05-15" name="CVE-2003-0308" modified="2008-11-11" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-305" source="DEBIAN" patch="1">DSA-305</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=235770" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=235770</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2008/10/30/2" source="MLIST">[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire</ref>
      <ref url="http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base" source="CONFIRM">http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base</ref>
      <ref url="http://bugs.debian.org/496408" source="CONFIRM">http://bugs.debian.org/496408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.12.3"/>
        <vers num="8.12.9"/>
        <vers num="8.9.3"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0309" published="2003-06-09" name="CVE-2003-0309" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/251788" source="CERT-VN">VU#251788</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12019" source="XF">ie-frame-restrictions-bypass(12019)</ref>
      <ref url="http://www.securityfocus.com/bid/7539" source="BID">7539</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-020.asp" source="MS">MS03-020</ref>
      <ref url="http://secunia.com/advisories/8807" source="SECUNIA">8807</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105294162726096&amp;w=2" source="NTBUGTRAQ" adv="1">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105294162726096&amp;w=2" source="NTBUGTRAQ">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105294081325040&amp;w=2" source="BUGTRAQ" adv="1">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105249399103214&amp;w=2" source="BUGTRAQ" adv="1">20030508 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! [CRITICAL]</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:948" source="OVAL" sig="1">oval:org.mitre.oval:def:948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0310" published="2003-06-16" name="CVE-2003-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105310013606680&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030516 EzPublish Directory XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ez_publish" name="ez_publish">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0312" published="2003-06-16" name="CVE-2003-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0313" published="2003-06-16" name="CVE-2003-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0314" published="2003-06-16" name="CVE-2003-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "&lt;/" sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0315" published="2003-06-16" name="CVE-2003-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105311719128173&amp;w=2" source="BUGTRAQ" adv="1">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowblind.net" name="snowblind_web_server">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0316" published="2003-06-16" name="CVE-2003-0316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm" source="MISC" patch="1">http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0188.html" source="BUGTRAQ" patch="1" adv="1">20030516 Venturi Client 2.1 confirmed as open relay [Verizon Wireless Mobile Office]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fourelle_venturi_wireless" name="venturi_client">
        <vers prev="1" num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0317" published="2003-12-31" name="CVE-2003-0317" modified="2008-10-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=25" source="IDEFENSE">20030522 Authentication Bypass in iisPROTECT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iisprotect" name="iisprotect">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0318" published="2003-06-09" name="CVE-2003-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105319538308834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030517 PHP-Nuke code injection in Yearly Stats at Statistics module</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0319" published="2003-06-09" name="CVE-2003-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105319299407291&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030517 Buffer overflow vulnerability found in MailMax version 5</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0072.html" source="VULNWATCH" patch="1" adv="1">20030517 Buffer overflow vulnerability found in MailMax version 5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartmax_software" name="mailmax">
        <vers prev="1" num="5.0.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0320" published="2003-06-09" name="CVE-2003-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105320172212990&amp;w=2" source="BUGTRAQ" adv="1">20030517 Remote code execution in ttCMS &lt;=v2.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andy_prevost" name="ttcms">
        <vers prev="1" num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0321" published="2003-06-09" name="CVE-2003-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled by the functions (1) send_ctcp, (2) cannot_join_channel, (3) cluster, (4) BX_compress_modes, (5) handle_oper_vision, and (6) ban_it.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-306" source="DEBIAN" patch="1" adv="1">DSA-306</ref>
      <ref url="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" source="MISC" patch="1">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852615211913&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030324 GLSA:  bitchx (200303-21)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766521328322&amp;w=2" source="BUGTRAQ" adv="1">20030313 Buffer overflows in ircII-based clients</ref>
      <ref url="http://www.securityfocus.com/bid/7100" source="BID">7100</ref>
      <ref url="http://www.securityfocus.com/bid/7099" source="BID">7099</ref>
      <ref url="http://www.securityfocus.com/bid/7097" source="BID">7097</ref>
      <ref url="http://www.securityfocus.com/bid/7096" source="BID">7096</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" source="CONECTIVA">CLA-2003:655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers prev="1" num="1.0.0c19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0322" published="2003-06-09" name="CVE-2003-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-306" source="DEBIAN" patch="1" adv="1">DSA-306</ref>
      <ref url="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" source="MISC" patch="1">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers prev="1" num="1.0.0c19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0323" published="2003-06-09" name="CVE-2003-0323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-291" source="DEBIAN" patch="1" adv="1">DSA-291</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104808915402926&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030319 [OpenPKG-SA-2003.024] OpenPKG Security Advisory (ircii)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766521328322&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030313 Buffer overflows in ircII-based clients</ref>
      <ref url="http://www.debian.org/security/2003/dsa-298" source="DEBIAN">DSA-298</ref>
      <ref url="http://www.securityfocus.com/bid/7098" source="BID">7098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_sandrof" name="ircii">
        <vers num="2002-09-12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0324" published="2003-06-09" name="CVE-2003-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-287" source="DEBIAN" patch="1" adv="1">DSA-287</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766521328322&amp;w=2" source="BUGTRAQ" adv="1">20030313 Buffer overflows in ircII-based clients</ref>
      <ref url="http://www.securityfocus.com/bid/7091" source="BID">7091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic" name="epic4">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0325" published="2003-06-09" name="CVE-2003-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105346309123217&amp;w=2" source="BUGTRAQ" adv="1">20030520 Maelstrom Local Buffer Overflow Exploit, FreeBSD 4.8 edition</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105344501331344&amp;w=2" source="BUGTRAQ" adv="1">20030519 Maelstrom exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105337792703887&amp;w=2" source="BUGTRAQ" adv="1">20030518 Maelstrom Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ambrosia_software" name="maelstrom">
        <vers prev="1" num="3.0.5"/>
        <vers num="3.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0326" published="2003-06-09" name="CVE-2003-0326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105337692202626&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030519 bazarr slocate</ref>
      <ref url="http://www.securityfocus.com/bid/7629" source="BID">7629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0327" published="2003-12-15" name="CVE-2003-0327" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0016.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0016.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13800" source="XF">sybase-passwordarray-bo(13800)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106936096103805&amp;w=2" source="BUGTRAQ">20031120 R7-0016: Sybase ASE 12.5 Remote Password Array Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="adaptive_server_enterprise">
        <vers num="12.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0328" published="2003-06-09" name="CVE-2003-0328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1" source="CONFIRM" patch="1" adv="1">ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-342.html" source="REDHAT">RHSA-2003:342</ref>
      <ref url="http://www.debian.org/security/2003/dsa-399" source="DEBIAN">DSA-399</ref>
      <ref url="http://www.debian.org/security/2003/dsa-306" source="DEBIAN">DSA-306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic" name="epic4">
        <vers num="pre2.002"/>
        <vers num="pre2.003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0329" published="2003-06-09" name="CVE-2003-0329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105344578100315&amp;w=2" source="BUGTRAQ" adv="1">20030520 Plaintext Password in Settings.ini of CesarFTP</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0074.html" source="VULNWATCH" adv="1">20030520 Plaintext Password in Settings.ini of CesarFTP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aclogic" name="cesarftp">
        <vers num="0.99g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0330" published="2003-06-09" name="CVE-2003-0330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105344891005369&amp;w=2" source="BUGTRAQ">20030520 Maelstrom Local Buffer Overflow Exploit</ref>
      <ref url="http://www.securitytracker.com/id?1008832" source="SECTRACK">1008832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ambrosia_software" name="maelstrom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0331" published="2003-06-09" name="CVE-2003-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105345273210334&amp;w=2" source="BUGTRAQ" adv="1">20030520 More vulnerabilities in ttForum/ttCMS -> SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ttcms" name="ttforum">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0332" published="2003-06-09" name="CVE-2003-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html" source="VULNWATCH" patch="1" adv="1">20030520 BadBlue Remote Administrative Interface Access Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105346382524169&amp;w=2" source="BUGTRAQ">20030520 BadBlue Remote Administrative Interface Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="working_resources_inc." name="badblue">
        <vers prev="1" num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0333" published="2003-05-19" name="CVE-2003-0333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/971364" source="CERT-VN" adv="1">VU#971364</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105190667523456&amp;w=2" source="BUGTRAQ" patch="1">20030502 Re: from bugtraq: HP-UX 11.0 /usr/bin/kermit (fwd)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11929" source="XF" adv="1">hp-ckermit-bo(11929)</ref>
      <ref url="http://www.securityfocus.com/bid/7627" source="BID" adv="1">7627</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105189670912220&amp;w=2" source="BUGTRAQ" adv="1">20030502 HP-UX 11.0 /usr/bin/kermit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0334" published="2003-05-10" name="CVE-2003-0334" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259643606984&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030510 BitchX: Crash when channel modes change</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" source="CONECTIVA" patch="1" adv="1">CLA-2003:655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12008" source="XF">bitchx-mode-change-dos(12008)</ref>
      <ref url="http://www.securityfocus.com/bid/7551" source="BID">7551</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:069" source="MANDRAKE">MDKSA-2003:069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers prev="1" num="1.0c20cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0335" published="2003-05-22" name="CVE-2003-0335" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105361968110719&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030522 [slackware-security]  quotacheck security fix in rc.M (SSA:2003-141-06)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0336" published="2003-05-22" name="CVE-2003-0336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly handled by Eudora.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362278914731&amp;w=2" source="BUGTRAQ" adv="1">20030522 Eudora 5.2.1 attachment spoof</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0337" published="2003-05-22" name="CVE-2003-0337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105361879109409&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030522 Security advisory: LSF 5.1 local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platform" name="lsadmin">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0338" published="2003-05-21" name="CVE-2003-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353168619211&amp;w=2" source="BUGTRAQ" adv="1">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0077.html" source="VULNWATCH" adv="1">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wsmp3" name="wsmp3_daemon">
        <vers num="0.0.10"/>
        <vers num="0.0.8"/>
        <vers num="0.0.9"/>
      </prod>
      <prod vendor="wsmp3" name="wsmp3_web_server">
        <vers num="0.0.1"/>
        <vers num="0.0.2"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0339" published="2003-05-22" name="CVE-2003-0339" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105361764807746&amp;w=2" source="BUGTRAQ" adv="1">20030522 WsMp3d remote exploit.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353178019353&amp;w=2" source="BUGTRAQ">20030521 Remote Heap Corruption Overflow vulnerability in WsMp3d.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353178019353&amp;w=2" source="VULNWATCH">20030521 Remote Heap Corruption Overflow vulnerability in WsMp3d.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wsmp3" name="wsmp3_daemon">
        <vers num="0.0.10"/>
        <vers num="0.0.8"/>
        <vers num="0.0.9"/>
      </prod>
      <prod vendor="wsmp3" name="wsmp3_web_server">
        <vers num="0.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0340" published="2003-05-21" name="CVE-2003-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0230.html" source="BUGTRAQ" adv="1">20030521 Demarc Puresecure v1.6 - Plaintext password issue -</ref>
    </refs>
    <vuln_soft>
      <prod vendor="demarc_security" name="puresecure">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0341" published="2003-05-21" name="CVE-2003-0341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353266220520&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030521 [AP] Owl Intranet Engine CSS Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="owl" name="owl_intranet_engine">
        <vers num="0.7"/>
        <vers num="0.71"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0342" published="2003-05-20" name="CVE-2003-0342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353283720837&amp;w=2" source="BUGTRAQ" adv="1">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="selom_ofori" name="blackmoon_ftp_server">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0343" published="2003-05-21" name="CVE-2003-0343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105353283720837&amp;w=2" source="BUGTRAQ" adv="1">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="selom_ofori" name="blackmoon_ftp_server">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0344" published="2003-06-16" name="CVE-2003-0344" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/679556" source="CERT-VN">VU#679556</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-020.asp" source="MS" patch="1" adv="1">MS03-020</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20030604.html" source="EEYE" patch="1" adv="1">AD20030604</ref>
      <ref url="http://secunia.com/advisories/8943" source="SECUNIA">8943</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006401.html" source="FULLDISC">20030709 IE Object Type Overflow Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105476381609135&amp;w=2" source="BUGTRAQ">20030604 Internet Explorer Object Type Property Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:922" source="OVAL" sig="1">oval:org.mitre.oval:def:922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":windows_server_2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0345" published="2003-08-18" name="CVE-2003-0345" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337764" source="CERT-VN">VU#337764</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12544" source="XF" patch="1" adv="1">win-smb-bo(12544)</ref>
      <ref url="http://www.securityfocus.com/bid/8152" source="BID" patch="1" adv="1">8152</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-024.asp" source="MS" patch="1" adv="1">MS03-024</ref>
      <ref url="http://securitytracker.com/id?1007154" source="SECTRACK">1007154</ref>
      <ref url="http://secunia.com/advisories/9225" source="SECUNIA">9225</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3391" source="OVAL" sig="1">oval:org.mitre.oval:def:3391</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:146" source="OVAL" sig="1">oval:org.mitre.oval:def:146</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:118" source="OVAL" sig="1">oval:org.mitre.oval:def:118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":terminal_server_alpha"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0346" published="2003-08-27" name="CVE-2003-0346" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-18.html" source="CERT" patch="1" adv="1">CA-2003-18</ref>
      <ref url="http://www.kb.cert.org/vuls/id/561284" source="CERT-VN">VU#561284</ref>
      <ref url="http://www.kb.cert.org/vuls/id/265232" source="CERT-VN">VU#265232</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-030.asp" source="MS" patch="1" adv="1">MS03-030</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105899759824008&amp;w=2" source="BUGTRAQ" adv="1">20030723 EEYE: Windows MIDI Decoder (QUARTZ.DLL) Heap Corruption</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:218" source="OVAL" sig="1">oval:org.mitre.oval:def:218</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1104" source="OVAL" sig="1">oval:org.mitre.oval:def:1104</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1095" source="OVAL" sig="1">oval:org.mitre.oval:def:1095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="5.2"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.0a"/>
        <vers num="8.1"/>
        <vers num="9.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0347" published="2003-10-20" name="CVE-2003-0347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/804780" source="CERT-VN">VU#804780</ref>
      <ref url="http://www.securityfocus.com/bid/8534" source="BID" patch="1" adv="1">8534</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-037.asp" source="MS" patch="1" adv="1">MS03-037</ref>
      <ref url="http://secunia.com/advisories/9666" source="SECUNIA">9666</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106262077829157&amp;w=2" source="BUGTRAQ" adv="1">20030903 EEYE: VBE Document Property Buffer Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.html" source="VULNWATCH">20030903 EEYE: VBE Document Property Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="xp" edition="sp1"/>
        <vers num="xp" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2000"/>
        <vers num="2002"/>
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":professional"/>
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":sdk"/>
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":sdk"/>
        <vers num="6.3" edition=""/>
        <vers num="6.3" edition=":sdk"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0348" published="2003-07-24" name="CVE-2003-0348" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/320516" source="CERT-VN">VU#320516</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-021.asp" source="MS" patch="1" adv="1">MS03-021</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12440" source="XF">mediaplayer-activex-obtain-information(12440)</ref>
      <ref url="http://www.securityfocus.com/bid/8034" source="BID">8034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0349" published="2003-07-24" name="CVE-2003-0349" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/113716" source="CERT-VN">VU#113716</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0306&amp;L=NTBUGTRAQ&amp;P=R4563" source="NTBUGTRAQ" patch="1" adv="1">20030626 Windows Media Services Remote Command Execution #2</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-022.asp" source="MS" patch="1" adv="1">MS03-022</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105665030925504&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030626 Windows Media Services Remote Command Execution #2</ref>
      <ref url="http://securitytracker.com/id?1007059" source="SECTRACK">1007059</ref>
      <ref url="http://secunia.com/advisories/9115" source="SECUNIA">9115</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:938" source="OVAL" sig="1">oval:org.mitre.oval:def:938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0350" published="2003-08-18" name="CVE-2003-0350" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.ngssoftware.com/advisories/utilitymanager.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/utilitymanager.txt</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-025.asp" source="MS" patch="1" adv="1">MS03-025</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105777681615939&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030709 Microsoft Utility Manager Local Privilege Escalation</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0015.html" source="VULNWATCH" patch="1" adv="1">20030709 Microsoft Utility Manager Local Privilege Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12543" source="XF">win2k-accessibility-gain-privileges</ref>
      <ref url="http://www.securityfocus.com/bid/8154" source="BID">8154</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:451" source="OVAL" sig="1">oval:org.mitre.oval:def:451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0351" reject="1" published="2003-12-31" name="CVE-2003-0351" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0306.  Reason: This candidate is a reservation duplicate of CVE-2003-0306.  Notes: All CVE users should reference CVE-2003-0306 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0352" published="2003-08-18" name="CVE-2003-0352" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/568148" source="CERT-VN">VU#568148</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-19.html" source="CERT">CA-2003-19</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-16.html" source="CERT">CA-2003-16</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12629" source="XF" patch="1" adv="1">win-rpc-dcom-bo(12629)</ref>
      <ref url="http://www.securityfocus.com/bid/8205" source="BID" patch="1" adv="1">8205</ref>
      <ref url="http://www.xfocus.org/documents/200307/2.html" source="MISC">http://www.xfocus.org/documents/200307/2.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-026.asp" source="MS">MS03-026</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007357.html" source="FULLDISC">20030730 rpcdcom Universal offsets</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007079.html" source="FULLDISC">20030726 Re: The French BUGTRAQ (New Win RPC Exploit)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105914789527294&amp;w=2" source="BUGTRAQ">20030725 The  Analysis  of LSD's Buffer Overrun in Windows RPC Interface(code revised )</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838687731618&amp;w=2" source="BUGTRAQ">20030716 [LSD] Critical security vulnerability in Microsoft Operating Systems</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:296" source="OVAL" sig="1">oval:org.mitre.oval:def:296</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2343" source="OVAL" sig="1">oval:org.mitre.oval:def:2343</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:194" source="OVAL" sig="1">oval:org.mitre.oval:def:194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0353" published="2003-08-27" name="CVE-2003-0353" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-033.asp" source="MS" patch="1" adv="1">MS03-033</ref>
      <ref url="http://www.securityfocus.com/bid/8455" source="BID">8455</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6954" source="OVAL">oval:org.mitre.oval:def:6954</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=106251069107953&amp;w=2" source="NTBUGTRAQ">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106149556627778&amp;w=2" source="BUGTRAQ">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:962" source="OVAL" sig="1">oval:org.mitre.oval:def:962</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:961" source="OVAL" sig="1">oval:org.mitre.oval:def:961</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1039" source="OVAL" sig="1">oval:org.mitre.oval:def:1039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1.3711.11" edition="ga"/>
        <vers num="2.12.4202.3"/>
        <vers num="2.5" edition="gold"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5" edition="sp2"/>
        <vers num="2.6" edition="gold"/>
        <vers num="2.6" edition="sp1"/>
        <vers num="2.6" edition="sp2"/>
        <vers num="2.7" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0354" published="2003-06-16" name="CVE-2003-0354" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-181.html" source="REDHAT" patch="1" adv="1">RHSA-2003:181</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-182.html" source="REDHAT">RHSA-2003:182</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:065" source="MANDRAKE">MDKSA-2003:065</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105465818929172&amp;w=2" source="BUGTRAQ">20030603 [OpenPKG-SA-2003.030] OpenPKG Security Advisory (ghostscript)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:133" source="OVAL" sig="1">oval:org.mitre.oval:def:133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0355" published="2003-06-09" name="CVE-2003-0355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/320707" source="BUGTRAQ">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0"/>
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0356" published="2003-06-09" name="CVE-2003-0356" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/641013" source="CERT-VN">VU#641013</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00009.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00009.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-313" source="DEBIAN" patch="1" adv="1">DSA-313</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067" source="MANDRAKE">MDKSA-2003:067</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:69" source="OVAL" sig="1">oval:org.mitre.oval:def:69</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0357" published="2003-06-09" name="CVE-2003-0357" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/361700" source="CERT-VN">VU#361700</ref>
      <ref url="http://www.kb.cert.org/vuls/id/232164" source="CERT-VN">VU#232164</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00009.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00009.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-313" source="DEBIAN" patch="1" adv="1">DSA-313</ref>
      <ref url="http://www.securityfocus.com/bid/7495" source="BID">7495</ref>
      <ref url="http://www.securityfocus.com/bid/7494" source="BID">7494</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067" source="MANDRAKE">MDKSA-2003:067</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:73" source="OVAL" sig="1">oval:org.mitre.oval:def:73</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0358" published="2003-06-09" name="CVE-2003-0358" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/311172/2003-02-08/2003-02-14/0" source="BUGTRAQ">20030209 #!ICadv-02.09.03: nethack 3.4.0 local buffer overflow</ref>
      <ref url="http://www.debian.org/security/2003/dsa-350" source="DEBIAN">DSA-350</ref>
      <ref url="http://www.debian.org/security/2003/dsa-316" source="DEBIAN">DSA-316</ref>
      <ref url="http://nethack.sourceforge.net/v340/bugmore/secpatch.txt" source="CONFIRM">http://nethack.sourceforge.net/v340/bugmore/secpatch.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11283" source="XF">nethack-s-command-bo(11283)</ref>
      <ref url="http://www.securityfocus.com/bid/6806" source="BID">6806</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0359" published="2003-07-24" name="CVE-2003-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-316" source="DEBIAN" patch="1" adv="1">DSA-316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stichting_mathematisch_centrum" name="nethack">
        <vers num="3.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0360" published="2003-06-09" name="CVE-2003-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-307" source="DEBIAN" patch="1" adv="1">DSA-307</ref>
      <ref url="http://gps.seul.org/changelog.html" source="CONFIRM" patch="1">http://gps.seul.org/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.9.1" edition=""/>
        <vers num="0.9.1" edition=":woody_gps_package"/>
        <vers num="0.9.2" edition=""/>
        <vers num="0.9.2" edition=":woody_gps_package"/>
        <vers num="0.9.3" edition=""/>
        <vers num="0.9.3" edition=":woody_gps_package"/>
        <vers num="0.9.4" edition=""/>
        <vers num="0.9.4" edition=":woody_gps_package"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0361" published="2003-06-09" name="CVE-2003-0361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-307" source="DEBIAN" patch="1" adv="1">DSA-307</ref>
      <ref url="http://gps.seul.org/changelog.html" source="CONFIRM" patch="1">http://gps.seul.org/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.9.1" edition=""/>
        <vers num="0.9.1" edition=":woody_gps_package"/>
        <vers num="0.9.2" edition=""/>
        <vers num="0.9.2" edition=":woody_gps_package"/>
        <vers num="0.9.3" edition=""/>
        <vers num="0.9.3" edition=":woody_gps_package"/>
        <vers num="0.9.4" edition=""/>
        <vers num="0.9.4" edition=":woody_gps_package"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0362" published="2003-06-09" name="CVE-2003-0362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-307" source="DEBIAN">DSA-307</ref>
      <ref url="http://gps.seul.org/changelog.html" source="CONFIRM">http://gps.seul.org/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.9.1" edition=""/>
        <vers num="0.9.1" edition=":woody_gps_package"/>
        <vers num="0.9.2" edition=""/>
        <vers num="0.9.2" edition=":woody_gps_package"/>
        <vers num="0.9.3" edition=""/>
        <vers num="0.9.3" edition=":woody_gps_package"/>
        <vers num="0.9.4" edition=""/>
        <vers num="0.9.4" edition=":woody_gps_package"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0363" published="2003-12-31" name="CVE-2003-0363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf" source="MISC" adv="1">http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="licq" name="licq">
        <vers num="1.0.3"/>
        <vers num="1.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0364" published="2003-06-16" name="CVE-2003-0364" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-187.html" source="REDHAT" patch="1" adv="1">RHSA-2003:187</ref>
      <ref url="http://www.debian.org/security/2003/dsa-311" source="DEBIAN" patch="1" adv="1">DSA-311</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-41.txt" source="TURBO" adv="1">TLSA-2003-41</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-195.html" source="REDHAT">RHSA-2003:195</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2003/dsa-336" source="DEBIAN">DSA-336</ref>
      <ref url="http://www.debian.org/security/2003/dsa-332" source="DEBIAN">DSA-332</ref>
      <ref url="http://www.debian.org/security/2003/dsa-312" source="DEBIAN">DSA-312</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:295" source="OVAL" sig="1">oval:org.mitre.oval:def:295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0365" published="2003-06-16" name="CVE-2003-0365" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables with malicious programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427404625027&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030529 ICQLite executable trojaning</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icq_inc" name="icqlite">
        <vers num="2003a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0366" published="2003-07-24" name="CVE-2003-0366" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-318" source="DEBIAN" patch="1" adv="1">DSA-318</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lysator" name="lyskom-server">
        <vers prev="1" num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0367" published="2003-07-02" name="CVE-2003-0367" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-38.txt" source="TURBO" patch="1" adv="1">TLSA-2003-38</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html" source="CONFIRM" patch="1" adv="1">http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-308" source="DEBIAN" patch="1" adv="1">DSA-308</ref>
      <ref url="http://www.securityfocus.com/bid/7872" source="BID">7872</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:068" source="MANDRAKE">MDKSA-2003:068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3.3_1.1.0"/>
        <vers prev="1" num="1.3.5"/>
        <vers prev="1" num="1.3.5_1.2.0"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="8.2"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1"/>
      </prod>
      <prod vendor="turbolinux" name="turbolinux_advanced_server">
        <vers num="6.0"/>
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="6.0"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0368" published="2004-02-03" name="CVE-2003-0368" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/924812" source="CERT-VN" patch="1" adv="1">VU#924812</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12221" source="XF" patch="1" adv="1">nokia-ggsn-ip-dos(12221)</ref>
      <ref url="http://www.securityfocus.com/bid/7854" source="BID" adv="1">7854</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a060903-1.txt" source="ATSTAKE">A060903-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="ggsn">
        <vers num="release_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0370" published="2003-06-16" name="CVE-2003-0370" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-192.html" source="REDHAT" patch="1" adv="1">RHSA-2003:192</ref>
      <ref url="http://www.kde.org/info/security/advisory-20030602-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20030602-1.txt</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-36.txt" source="TURBO">TLSA-2003-36</ref>
      <ref url="http://www.securityfocus.com/archive/1/320707" source="BUGTRAQ" adv="1">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-193.html" source="REDHAT">RHSA-2003:193</ref>
      <ref url="http://www.debian.org/security/2003/dsa-361" source="DEBIAN">DSA-361</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.html" source="FULLDISC">20030510 [forward]Apple Safari and Konqueror Embedded Common Name Verification Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/7520" source="BID">7520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="0.1"/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers prev="1" num="2.2.2"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0371" published="2003-06-16" name="CVE-2003-0371" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370592729044&amp;w=2" source="BUGTRAQ">20030522 Prishtina FTP v.1.*: remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prishtina_soft" name="prishtina_ftp">
        <vers num="v.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0372" published="2003-06-16" name="CVE-2003-0372" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105369506714849&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030523 nessus NASL scripting engine security issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105364059803427&amp;w=2" source="BUGTRAQ" patch="1">20030522 Potential security vulnerability in Nessus</ref>
      <ref url="http://www.securityfocus.com/bid/7664" source="BID">7664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0373" published="2003-06-16" name="CVE-2003-0373" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105364059803427&amp;w=2" source="BUGTRAQ" patch="1">20030522 Potential security vulnerability in Nessus</ref>
      <ref url="http://www.securityfocus.com/bid/7664" source="BID">7664</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105369506714849&amp;w=2" source="BUGTRAQ">20030523 nessus NASL scripting engine security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0374" published="2003-06-16" name="CVE-2003-0374" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7664" source="BID">7664</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105364059803427&amp;w=2" source="BUGTRAQ">20030522 Potential security vulnerability in Nessus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0375" published="2003-06-16" name="CVE-2003-0375" modified="2008-10-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7662" source="BID">7662</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105363936402228&amp;w=2" source="BUGTRAQ" adv="1">20030522 XMB 1.8 Partagium cross site scripting vulnerability</ref>
      <ref url="http://forums.xmbforum.com/viewthread.php?tid=773046" source="MISC">http://forums.xmbforum.com/viewthread.php?tid=773046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.11"/>
        <vers num="1.6"/>
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0376" published="2003-06-16" name="CVE-2003-0376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large number of . (dot) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370625529452&amp;w=2" source="BUGTRAQ" adv="1">20030523 Eudora 5.2.1 buffer overflow DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0377" published="2003-06-16" name="CVE-2003-0377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370528728225&amp;w=2" source="BUGTRAQ" patch="1">20030523 iisPROTECT SQL injection in admin interface</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iisprotect" name="iisprotect">
        <vers num="2.2_r4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0378" published="2003-06-16" name="CVE-2003-0378" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/467828" source="CERT-VN" patch="1" adv="1">VU#467828</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=107579" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=107579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0379" published="2003-07-24" name="CVE-2003-0379" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00030.html" source="CONFIRM" patch="1" adv="1">http://lists.apple.com/mhonarc/security-announce/msg00030.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="afp_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0380" published="2003-07-02" name="CVE-2003-0380" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-314" source="DEBIAN" patch="1" adv="1">DSA-314</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0056.html" source="BUGTRAQ" patch="1" adv="1">20030606 atftpd bug</ref>
      <ref url="http://www.securityfocus.com/archive/82/323886/2003-06-02/2003-06-08/0" source="VULN-DEV" adv="1">20030604 possible remote buffer overflow in atftpd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atftpd" name="atftpd">
        <vers num="0.6.0"/>
        <vers num="0.6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0381" published="2003-07-24" name="CVE-2003-0381" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-323" source="DEBIAN" patch="1" adv="1">DSA-323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="norman_ramsey" name="noweb">
        <vers prev="1" num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0382" published="2003-07-02" name="CVE-2003-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-309" source="DEBIAN" patch="1" adv="1">DSA-309</ref>
      <ref url="http://www.securityfocus.com/bid/7708" source="BID">7708</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105427580626001&amp;w=2" source="BUGTRAQ">20030509 BAZARR CODE NINER PINK TEAM GO GO GO</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.3"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0385" published="2003-07-02" name="CVE-2003-0385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-310" source="DEBIAN" patch="1" adv="1">DSA-310</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105491469815197&amp;w=2" source="BUGTRAQ" adv="1">20030605 BAZARR LOCAL ROOT AGAIN. HI GUYS. DONT READ THIS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0.18" edition=""/>
        <vers num="3.0.18" edition=":potato"/>
        <vers num="3.0.23" edition=""/>
        <vers num="3.0.23" edition=":woody"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0386" published="2003-07-02" name="CVE-2003-0386" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/978316" source="CERT-VN" patch="1" adv="1">VU#978316</ref>
      <ref url="http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0" source="BUGTRAQ" patch="1" adv="1">20030605 OpenSSH remote clent address restriction circumvention</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9894" source="OVAL">oval:org.mitre.oval:def:9894</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00038.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
      <ref url="http://www.securityfocus.com/bid/7831" source="BID">7831</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0698.html" source="REDHAT">RHSA-2006:0698</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0298.html" source="REDHAT">RHSA-2006:0298</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm</ref>
      <ref url="http://secunia.com/advisories/23680" source="SECUNIA">23680</ref>
      <ref url="http://secunia.com/advisories/22196" source="SECUNIA">22196</ref>
      <ref url="http://secunia.com/advisories/21724" source="SECUNIA">21724</ref>
      <ref url="http://secunia.com/advisories/21262" source="SECUNIA">21262</ref>
      <ref url="http://secunia.com/advisories/21129" source="SECUNIA">21129</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" source="SGI">20060703-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0388" published="2003-07-24" name="CVE-2003-0388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/06.16.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/06.16.03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105577915506761&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030616 FW: iDEFENSE Security Advisory 06.16.03: Linux-PAM getlogin() Spoofing</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-304.html" source="REDHAT">RHSA-2004:304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_morgan" name="linux_pam">
        <vers prev="1" num="0.77"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0389" published="2003-07-24" name="CVE-2003-0389" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0014.html" source="MISC" patch="1" adv="1">http://www.rapid7.com/advisories/R7-0014.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0112.html" source="VULNWATCH" patch="1" adv="1">20030619 R7-0014: RSA SecurID ACE Agent Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="ace_agent">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0390" published="2003-07-02" name="CVE-2003-0390" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz" source="CONFIRM" patch="1">http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105371246204866&amp;w=2" source="BUGTRAQ">20030523 Re: Options Parsing Tool library buffer overflows.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105121918523320&amp;w=2" source="BUGTRAQ">20030424 SRT2003-04-24-1532 -  Options Parsing Tool library buffer overflows.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="james_theiler" name="opt">
        <vers prev="1" num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0391" published="2003-07-02" name="CVE-2003-0391" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.magicwinmail.net/changelog.asp" source="MISC">http://www.magicwinmail.net/changelog.asp</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105370528428222&amp;w=2" source="BUGTRAQ">20030523 Magic Winmail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amax_information_technologies" name="magic_winmail_server">
        <vers prev="1" num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0392" published="2003-07-02" name="CVE-2003-0392" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive letter argument (e.g. E:).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105372353017778&amp;w=2" source="BUGTRAQ">20030523 ST FTP Service v3.0: directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="st" name="ftp_service">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0393" published="2003-07-02" name="CVE-2003-0393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services via FIN scans or Xmas scans.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7700" source="BID">7700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105380229532320&amp;w=2" source="BUGTRAQ">20030524 Some problems in Privatefirewall 3.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="privacyware" name="privatefirewall">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0394" published="2003-07-02" name="CVE-2003-0394" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105379530927567&amp;w=2" source="BUGTRAQ" patch="1">20030524 PHP source code injection in BLNews</ref>
      <ref url="http://www.securityfocus.com/bid/7677" source="BID">7677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blnews" name="blnews">
        <vers num="2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0395" published="2003-07-02" name="CVE-2003-0395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105379741528925&amp;w=2" source="BUGTRAQ">20030524 UPB: Discussion Board/Web-Site Takeover</ref>
      <ref url="http://f0kp.iplus.ru/bz/024.en.txt" source="MISC">http://f0kp.iplus.ru/bz/024.en.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_outburst" name="ultimate_php_board_upb">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0396" published="2003-07-02" name="CVE-2003-0396" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=156242" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=156242</ref>
      <ref url="http://www.securityfocus.com/bid/7437" source="BID">7437</ref>
      <ref url="http://www.securiteam.com/exploits/5EP0M1P9PO.html" source="MISC">http://www.securiteam.com/exploits/5EP0M1P9PO.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154433926396&amp;w=2" source="BUGTRAQ">20030428 ATM  on Linux Exploit Code Release (les, local)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11903" source="XF">atmonlinux-les-command-bo(11903)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405560021979&amp;w=2" source="BUGTRAQ">20030524 ATM on linux Exploit(les,local)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux-atm" name="linux-atm">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0397" published="2003-07-02" name="CVE-2003-0397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7680" source="BID">7680</ref>
      <ref url="http://www.iss.net/security_center/static/12086.php" source="XF">fastrack-packet-0-bo(12086)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405708923565&amp;w=2" source="BUGTRAQ">20030526 The PACKET 0' DEATH FastTrack network vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sharman_networks" name="kazaa">
        <vers num="v2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0398" published="2003-07-02" name="CVE-2003-0398" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7685" source="BID" patch="1" adv="1">7685</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-016-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-016-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12077.php" source="XF" patch="1" adv="1">vignette-ssi-command-execution(12077)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405734223874&amp;w=2" source="BUGTRAQ">20030526 S21SEC-016 - Vignette SSI Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0399" published="2003-07-02" name="CVE-2003-0399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-017-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-017-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12076.php" source="XF" patch="1" adv="1">vignette-save-obtain-information(12076)</ref>
      <ref url="http://www.securityfocus.com/bid/7683" source="BID">7683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405874325673&amp;w=2" source="BUGTRAQ">20030526 S21SEC-017 - Vignette /vgn/legacy/save SQL access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0400" published="2003-06-30" name="CVE-2003-0400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/12075.php" source="XF" patch="1" adv="1">vignette-memory-leak(12075)</ref>
      <ref url="http://www.securityfocus.com/bid/7684" source="BID" adv="1">7684</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-018-en.txt" source="MISC" adv="1">http://www.s21sec.com/es/avisos/s21sec-018-en.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405985126857&amp;w=2" source="BUGTRAQ">20030526 S21SEC-018 - Vignette memory leak AIX Platform</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="6.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0401" published="2003-06-30" name="CVE-2003-0401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7688" source="BID" adv="1">7688</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-019-en.txt" source="MISC" adv="1">http://www.s21sec.com/es/avisos/s21sec-019-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12074.php" source="XF" adv="1">vignette-style-info-disclosure(12074)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405793324661&amp;w=2" source="BUGTRAQ">20030526 S21SEC-019 - Vignette /vgn/style internal information leak</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0402" published="2003-06-30" name="CVE-2003-0402" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.s21sec.com/en/avisos/s21sec-020-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/en/avisos/s21sec-020-en.txt</ref>
      <ref url="http://www.securityfocus.com/bid/7691" source="BID" adv="1">7691</ref>
      <ref url="http://www.iss.net/security_center/static/12073.php" source="XF" adv="1">vignette-login-account-bruteforce(12073)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405880325755&amp;w=2" source="BUGTRAQ">20030526 S21SEC-020 - Vignette user enumeration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0403" published="2003-06-30" name="CVE-2003-0403" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-021-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-021-en.txt</ref>
      <ref url="http://www.securityfocus.com/bid/7694" source="BID" adv="1">7694</ref>
      <ref url="http://www.iss.net/security_center/static/12072.php" source="XF" adv="1">vignette-license-modification(12072)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405789924612&amp;w=2" source="BUGTRAQ">20030526 S21SEC-021 - Vignette License access and modification</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0404" published="2003-06-30" name="CVE-2003-0404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7687" source="BID" patch="1" adv="1">7687</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-023-en.txt" source="MISC" adv="1">http://www.s21sec.com/es/avisos/s21sec-023-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12071.php" source="XF" adv="1">vignette-multiple-xss(12071)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406028027360&amp;w=2" source="BUGTRAQ">20030526 S21SEC-023 -  Vignette multiple Cross Site Scripting vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0405" published="2003-06-30" name="CVE-2003-0405" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7692" source="BID" patch="1" adv="1">7692</ref>
      <ref url="http://www.securityfocus.com/bid/7690" source="BID" patch="1" adv="1">7690</ref>
      <ref url="http://www.s21sec.com/es/avisos/s21sec-024-en.txt" source="MISC" patch="1" adv="1">http://www.s21sec.com/es/avisos/s21sec-024-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/12070.php" source="XF" adv="1">vignette-tcl-code-execution(12070)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405922826197&amp;w=2" source="BUGTRAQ">20030526 S21SEC-024 - Vignette TCL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="content_suite">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod vendor="vignette" name="storyserver">
        <vers num="5.0"/>
      </prod>
      <prod vendor="vignette" name="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0406" published="2003-06-30" name="CVE-2003-0406" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7696" source="BID" adv="1">7696</ref>
      <ref url="http://www.iss.net/security_center/static/12083.php" source="XF" adv="1">palmvnc-plaintext-passwords(12083)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405691423389&amp;w=2" source="BUGTRAQ" adv="1">20030526 PalmVNC 1.40 Insecure Records</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palmvnc" name="palmvnc">
        <vers num="1.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0407" published="2003-06-30" name="CVE-2003-0407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7699" source="BID" adv="1">7699</ref>
      <ref url="http://www.iss.net/security_center/static/12087.php" source="XF" adv="1">batalla-naval-bo(12087)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405668423102&amp;w=2" source="BUGTRAQ" adv="1">20030526 [Priv8security_Advisory]_Batalla_Naval_remote_overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="batalla_naval">
        <vers num="1.0_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0408" published="2003-06-30" name="CVE-2003-0408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7703" source="BID" patch="1" adv="1">7703</ref>
      <ref url="http://www.iss.net/security_center/static/12131.php" source="XF" patch="1" adv="1">upclient-command-line-bo(12131)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405629622652&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030527 NuxAcid#002 - Buffer Overflow in UpClient</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_uptimes_project" name="upclient">
        <vers num="5.0b7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0409" published="2003-06-30" name="CVE-2003-0409" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7695" source="BID" adv="1">7695</ref>
      <ref url="http://www.iss.net/security_center/static/12107.php" source="XF" adv="1">webweaver-head-post-bo(12107)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105405836025160&amp;w=2" source="BUGTRAQ" adv="1">20030527 BRS WebWeaver: POST and HEAD Overflaws</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brs" name="webweaver">
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0410" published="2003-06-30" name="CVE-2003-0410" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7681" source="BID" patch="1" adv="1">7681</ref>
      <ref url="http://www.iss.net/security_center/static/12068.php" source="XF" patch="1" adv="1">analogx-proxy-url-bo(12068)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105406759403978&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0082.html" source="VULNWATCH" patch="1" adv="1">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</ref>
      <ref url="http://www.analogx.com/contents/download/network/proxy.htm" source="CONFIRM" adv="1">http://www.analogx.com/contents/download/network/proxy.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="proxy">
        <vers num="4.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0411" published="2003-06-30" name="CVE-2003-0411" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7709" source="BID" patch="1" adv="1">7709</ref>
      <ref url="http://www.iss.net/security_center/static/12093.php" source="XF" patch="1" adv="1">sunone-jsp-source-disclosure(12093)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" patch="1" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" patch="1" adv="1">55221</ref>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":standard"/>
        <vers num="7.0" edition=":platform"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0412" published="2003-06-30" name="CVE-2003-0412" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7711" source="BID" patch="1" adv="1">7711</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" patch="1" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" patch="1" adv="1">55221</ref>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0413" published="2003-06-30" name="CVE-2003-0413" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7710" source="BID" patch="1" adv="1">7710</ref>
      <ref url="http://www.iss.net/security_center/static/12095.php" source="XF" patch="1" adv="1">sunone-http-error-xss(12095)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" patch="1" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" patch="1" adv="1">55221</ref>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201009-1" source="SUNALERT">201009</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57605" source="SUNALERT">57605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0414" published="2003-06-30" name="CVE-2003-0414" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.spidynamics.com/sunone_alert.html" source="MISC">http://www.spidynamics.com/sunone_alert.html</ref>
      <ref url="http://www.securityfocus.com/bid/7712" source="BID" adv="1">7712</ref>
      <ref url="http://www.iss.net/security_center/static/12096.php" source="XF" adv="1">sunone-insecure-file-permissions(12096)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-103.shtml" source="CIAC" adv="1">N-103</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1" source="SUNALERT">1000610</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" source="SUNALERT" adv="1">55221</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105409846029475&amp;w=2" source="BUGTRAQ" adv="1">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0415" published="2003-06-30" name="CVE-2003-0415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ytech.co.il/advisories/rpca/rpcaccess.htm" source="MISC" patch="1" adv="1">http://www.ytech.co.il/advisories/rpca/rpcaccess.htm</ref>
      <ref url="http://www.securityfocus.com/bid/7698" source="BID" patch="1" adv="1">7698</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105417988811698&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030528 Remote PC Access Server  2.2 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="access-remote-pc.com" name="remote_pc_access">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0416" published="2003-06-30" name="CVE-2003-0416" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7729" source="BID" adv="1">7729</ref>
      <ref url="http://www.iss.net/security_center/static/12108.php" source="XF" adv="1">bandmin-index-xss(12108)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418152212771&amp;w=2" source="BUGTRAQ" adv="1">20030528 Bandmin 1.4 XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bandmin" name="bandmin">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0417" published="2003-06-30" name="CVE-2003-0417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7717" source="BID" adv="1">7717</ref>
      <ref url="http://www.iss.net/security_center/static/12103.php" source="XF" adv="1">sonhserver-pipe-directory-traversal(12103)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105417983711685&amp;w=2" source="BUGTRAQ" adv="1">20030529 Son hServer v0.2: directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="super-m" name="son_hserver">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0418" published="2003-07-24" name="CVE-2003-0418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/471084" source="CERT-VN" patch="1" adv="1">VU#471084</ref>
      <ref url="http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt" source="MISC" patch="1" adv="1">http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105519179005065&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030609 Linux 2.0 remote info leak from too big icmp citation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.3"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0419" published="2003-07-24" name="CVE-2003-0419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/advisory/06.11.03.txt" source="MISC" patch="1" adv="1">http://www.idefense.com/advisory/06.11.03.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smc_networks" name="barricade_wireless_cable_dsl_broadband_router">
        <vers num="smc7004vwbr"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0420" published="2003-06-13" name="CVE-2003-0420" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JPLA-5NTL8E" source="MISC" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JPLA-5NTL8E</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12342" source="XF" patch="1" adv="1">macos-dsimportexport-obtain-information(12342)</ref>
      <ref url="http://www.securityfocus.com/bid/7894" source="BID" patch="1" adv="1">7894</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3165" source="AUSCERT" patch="1" adv="1">ESB-2003.0415</ref>
      <ref url="http://secunia.com/advisories/9025/" source="SECUNIA" patch="1" adv="1">9025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0421" published="2003-08-27" name="CVE-2003-0421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0422" published="2003-08-27" name="CVE-2003-0422" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0423" published="2003-08-27" name="CVE-2003-0423" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0424" published="2003-08-27" name="CVE-2003-0424" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0425" published="2003-08-27" name="CVE-2003-0425" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0426" published="2003-08-27" name="CVE-2003-0426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0427" published="2003-07-24" name="CVE-2003-0427" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-320" source="DEBIAN" patch="1" adv="1">DSA-320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10194" source="OVAL">oval:org.mitre.oval:def:10194</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-506.html" source="REDHAT">RHSA-2005:506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:647" source="OVAL" sig="1">oval:org.mitre.oval:def:647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miod_vallat" name="mikmod">
        <vers num="3.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0428" published="2003-07-24" name="CVE-2003-0428" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/542540" source="CERT-VN">VU#542540</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:75" source="OVAL" sig="1">oval:org.mitre.oval:def:75</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0429" published="2003-07-24" name="CVE-2003-0429" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:84" source="OVAL" sig="1">oval:org.mitre.oval:def:84</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0430" published="2003-07-24" name="CVE-2003-0430" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:88" source="OVAL" sig="1">oval:org.mitre.oval:def:88</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0431" published="2003-07-24" name="CVE-2003-0431" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:101" source="OVAL" sig="1">oval:org.mitre.oval:def:101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0432" published="2003-07-24" name="CVE-2003-0432" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-324" source="DEBIAN" patch="1" adv="1">DSA-324</ref>
      <ref url="http://secunia.com/advisories/9007" source="SECUNIA">9007</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt" source="SCO">CSSA-2003-030.0</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-077.html" source="REDHAT">RHSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662" source="CONECTIVA">CLA-2003:662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:106" source="OVAL" sig="1">oval:org.mitre.oval:def:106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0433" published="2003-07-24" name="CVE-2003-0433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in gnocatan 0.6.1 and earlier allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-315" source="DEBIAN" patch="1" adv="1">DSA-315</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnocatan-develop" name="gnocatan">
        <vers prev="1" num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0434" published="2003-07-24" name="CVE-2003-0434" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/200132" source="CERT-VN">VU#200132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-197.html" source="REDHAT" patch="1" adv="1">RHSA-2003:197</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-196.html" source="REDHAT" patch="1" adv="1">RHSA-2003:196</ref>
      <ref url="http://secunia.com/advisories/9038" source="SECUNIA">9038</ref>
      <ref url="http://secunia.com/advisories/9037" source="SECUNIA">9037</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105777963019186&amp;w=2" source="BUGTRAQ">20030709 xpdf vulnerability - CAN-2003-0434</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.html" source="FULLDISC">20030613 -10Day CERT Advisory on PDF Files</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:071" source="MANDRAKE">MDKSA-2003:071</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:664" source="OVAL" sig="1">oval:org.mitre.oval:def:664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="5.0.6"/>
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="1.1"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0435" published="2003-07-24" name="CVE-2003-0435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-322" source="DEBIAN" patch="1" adv="1">DSA-322</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105553002105111&amp;w=2" source="BUGTRAQ" adv="1">20030612 BAZARR THUG LIFE , DONT READ OR VIRUS INFECT YOU</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typespeed" name="typespeed">
        <vers prev="1" num="0.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0436" published="2003-07-24" name="CVE-2003-0436" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7865" source="BID" patch="1" adv="1">7865</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html" source="FULLDISC">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0437" published="2003-07-24" name="CVE-2003-0437" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7866" source="BID" patch="1" adv="1">7866</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html" source="FULLDISC">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0438" published="2003-07-24" name="CVE-2003-0438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-325" source="DEBIAN" patch="1" adv="1">DSA-325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yuuichi_teranishi" name="eldav">
        <vers prev="1" num="0.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0440" published="2003-08-18" name="CVE-2003-0440" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-234.html" source="REDHAT" patch="1" adv="1">RHSA-2003:234</ref>
      <ref url="http://www.debian.org/security/2003/dsa-339" source="DEBIAN" patch="1" adv="1">DSA-339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-231.html" source="REDHAT">RHSA-2003:231</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:569" source="OVAL" sig="1">oval:org.mitre.oval:def:569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="semi" name="semi">
        <vers num="1.14.3"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0441" published="2004-03-03" name="CVE-2003-0441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7988" source="BID" patch="1" adv="1">7988</ref>
      <ref url="http://www.debian.org/security/2003/dsa-326" source="DEBIAN" patch="1" adv="1">DSA-326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12381" source="XF" adv="1">orvillewrite-variables-bo(12381)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orville-write" name="orville-write">
        <vers num="2.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0442" published="2003-07-24" name="CVE-2003-0442" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-204.html" source="REDHAT" patch="1" adv="1">RHSA-2003:204</ref>
      <ref url="http://shh.thathost.com/secadv/2003-05-11-php.txt" source="MISC" patch="1" adv="1">http://shh.thathost.com/secadv/2003-05-11-php.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105760591228031&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)</ref>
      <ref url="http://www.securityfocus.com/bid/7761" source="BID">7761</ref>
      <ref url="http://www.debian.org/security/2003/dsa-351" source="DEBIAN">DSA-351</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105449314612963&amp;w=2" source="BUGTRAQ" adv="1">20030530 PHP Trans SID  XSS (Was: New php release with security fixes)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12259" source="XF">php-session-id-xss(12259)</ref>
      <ref url="http://www.turbolinux.co.jp/security/2003/TLSA-2003-47j.txt" source="TURBO">TLSA-2003-47</ref>
      <ref url="http://www.securitytracker.com/id?1008653" source="SECTRACK">1008653</ref>
      <ref url="http://www.osvdb.org/4758" source="OSVDB">4758</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:082" source="MANDRAKE">MDKSA-2003:082</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-112.shtml" source="CIAC">N-112</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691" source="CONECTIVA">CLSA-2003:691</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:485" source="OVAL" sig="1">oval:org.mitre.oval:def:485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.3.1"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0444" published="2004-03-29" name="CVE-2003-0444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12462" source="XF" patch="1" adv="1">gtksee-png-bo(12462)</ref>
      <ref url="http://www.securityfocus.com/bid/8061" source="BID" patch="1" adv="1">8061</ref>
      <ref url="http://www.debian.org/security/2003/dsa-337" source="DEBIAN" patch="1" adv="1">DSA-337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtksee" name="gtksee">
        <vers num="0.5"/>
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0445" published="2003-07-24" name="CVE-2003-0445" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-328" source="DEBIAN" patch="1" adv="1">DSA-328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfs" name="webfs">
        <vers prev="1" num="1.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0446" published="2003-07-24" name="CVE-2003-0446" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://security.greymagic.com/adv/gm013-ie/" source="MISC" adv="1">http://security.greymagic.com/adv/gm013-ie/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105585001905002&amp;w=2" source="NTBUGTRAQ" adv="1">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105595990924165&amp;w=2" source="BUGTRAQ" adv="1">20030617 Re: [Full-Disclosure] Cross-Site Scripting in Unparsable XML Files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105585986015421&amp;w=2" source="BUGTRAQ" adv="1">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005762.html" source="FULLDISC">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12334" source="XF">ie-msxml-xss(12334)</ref>
      <ref url="http://www.securityfocus.com/bid/7938" source="BID">7938</ref>
      <ref url="http://www.osvdb.org/3065" source="OSVDB">3065</ref>
      <ref url="http://secunia.com/advisories/9055" source="SECUNIA">9055</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0120.html" source="BUGTRAQ">20030617 Re: Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0447" published="2003-07-24" name="CVE-2003-0447" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://security.greymagic.com/adv/gm014-ie/" source="MISC" adv="1">http://security.greymagic.com/adv/gm014-ie/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105585142406147&amp;w=2" source="NTBUGTRAQ" adv="1">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105585933614773&amp;w=2" source="BUGTRAQ" adv="1">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html" source="FULLDISC">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0448" published="2003-07-24" name="CVE-2003-0448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105588111714856&amp;w=2" source="BUGTRAQ" adv="1">20030618 Portmon file arbitrary read/write access vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aboleo.net" name="portmon">
        <vers prev="1" num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0449" published="2003-08-07" name="CVE-2003-0449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt" source="MISC" patch="1" adv="1">http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt</ref>
      <ref url="http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt" source="MISC" patch="1" adv="1">http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105561189625082&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030614 SRT2003-06-13-1009 - Progress _dbagent -installdir dlopen() issue</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105561134624665&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030614 SRT2003-06-13-0945 - Progress PATH based dlopen() issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="progress" name="database">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0450" published="2003-08-07" name="CVE-2003-0450" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-40.txt" source="TURBO" patch="1" adv="1">TLSA-2003-40</ref>
      <ref url="http://www.debian.org/security/2003/dsa-321" source="DEBIAN" patch="1" adv="1">DSA-321</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063" source="MISC" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_030_radiusd_cistron.html" source="SUSE">SuSE-SA:2003:030</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000664" source="CONECTIVA">CLA-2003:664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cistron" name="radius_daemon">
        <vers prev="1" num="1.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0451" published="2003-08-07" name="CVE-2003-0451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-327" source="DEBIAN" patch="1" adv="1">DSA-327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xblockout" name="xbl">
        <vers prev="1" num="1.0j"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0452" published="2003-08-07" name="CVE-2003-0452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-329" source="DEBIAN" patch="1" adv="1">DSA-329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gunnar_ritter" name="osh">
        <vers prev="1" num="1.7-10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0453" published="2003-08-07" name="CVE-2003-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-348" source="DEBIAN">DSA-348</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105613905425563&amp;w=2" source="BUGTRAQ" adv="1">20030620 BAZARR FAREWELL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ehud_gavron" name="traceroute-nanog">
        <vers num="6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0454" published="2003-08-07" name="CVE-2003-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-334" source="DEBIAN">DSA-334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_rumsey" name="xgalaga">
        <vers num="2.0.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0455" published="2003-08-07" name="CVE-2003-0455" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-331" source="DEBIAN" patch="1" adv="1">DSA-331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-494.html" source="REDHAT">RHSA-2004:494</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105786393628728&amp;w=2" source="BUGTRAQ">20030710 [OpenPKG-SA-2003.034] OpenPKG Security Advisory (imagemagick)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="libmagick_library">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0456" published="2003-08-18" name="CVE-2003-0456" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8075" source="BID" patch="1" adv="1">8075</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105733894003737&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030701 VisNetic WebSite Path Disclosure Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0002.html" source="VULNWATCH" patch="1" adv="1">20030701 VisNetic WebSite Path Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12483" source="XF">visnetic-website-path-disclosure(12483)</ref>
      <ref url="http://www.krusesecurity.dk/advisories/vis0103.txt" source="MISC">http://www.krusesecurity.dk/advisories/vis0103.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="visnetic_website">
        <vers num="3.5.13"/>
        <vers num="3.5.15"/>
        <vers num="3.5.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0458" published="2003-08-18" name="CVE-2003-0458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8080" source="BID" patch="1" adv="1">8080</ref>
      <ref url="http://www.securityfocus.com/advisories/5545" source="HP" adv="1">SSRT3488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="nonstop_seeview_server_gateway">
        <vers num="d40.00"/>
        <vers num="d41.00"/>
        <vers num="d42.00"/>
        <vers num="d42.01"/>
        <vers num="d43.00"/>
        <vers num="d43.01"/>
        <vers num="d43.02"/>
        <vers num="d44.00"/>
        <vers num="d44.01"/>
        <vers num="d44.02"/>
        <vers num="d45.00"/>
        <vers num="d45.01"/>
        <vers num="d46.00"/>
        <vers num="d47.00"/>
        <vers num="d48.00"/>
        <vers num="d48.01"/>
        <vers num="d48.02"/>
        <vers num="d48.03"/>
        <vers num="g01.00"/>
        <vers num="g02.00"/>
        <vers num="g03.00"/>
        <vers num="g04.00"/>
        <vers num="g05.00"/>
        <vers num="g05.01"/>
        <vers num="g06.00"/>
        <vers num="g06.01"/>
        <vers num="g06.03"/>
        <vers num="g06.04"/>
        <vers num="g06.05"/>
        <vers num="g06.06"/>
        <vers num="g06.07"/>
        <vers num="g06.08"/>
        <vers num="g06.09"/>
        <vers num="g06.10"/>
        <vers num="g06.11"/>
        <vers num="g06.12"/>
        <vers num="g06.13"/>
        <vers num="g06.14"/>
        <vers num="g06.15"/>
        <vers num="g06.16"/>
        <vers num="g06.17"/>
        <vers num="g06.18"/>
        <vers num="g06.19"/>
        <vers num="g06.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0459" published="2003-08-27" name="CVE-2003-0459" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-236.html" source="REDHAT" patch="1" adv="1">RHSA-2003:236</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-235.html" source="REDHAT" patch="1" adv="1">RHSA-2003:235</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105986238428061&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030802 [slackware-security]  KDE packages updated (SSA:2003-213-01)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-45.txt" source="TURBO">TLSA-2003-45</ref>
      <ref url="http://www.kde.org/info/security/advisory-20030729-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20030729-1.txt</ref>
      <ref url="http://www.debian.org/security/2003/dsa-361" source="DEBIAN">DSA-361</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007300.html" source="FULLDISC">20030729 KDE Security Advisory: Konqueror Referrer Authentication Leak</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:079" source="MANDRAKE">MDKSA-2003:079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747" source="CONECTIVA">CLA-2003:747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:411" source="OVAL" sig="1">oval:org.mitre.oval:def:411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.5"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="0.1"/>
      </prod>
      <prod vendor="redhat" name="analog_real-time_synthesizer">
        <vers num="2.1.1-5" edition=""/>
        <vers num="2.1.1-5" edition=":i386"/>
        <vers num="2.2-11" edition=""/>
        <vers num="2.2-11" edition=":ia64"/>
        <vers num="2.2-11" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="3.0.3-13" edition=""/>
        <vers num="3.0.3-13" edition=":i386_dev"/>
        <vers num="3.0.3-13" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="kdelibs">
        <vers num="2.1.1-5" edition=""/>
        <vers num="2.1.1-5" edition=":i386"/>
        <vers num="2.2-11" edition=""/>
        <vers num="2.2-11" edition=":ia64"/>
        <vers num="2.2-11" edition=":i386"/>
        <vers num="3.0.0-10" edition=""/>
        <vers num="3.0.0-10" edition=":i386"/>
        <vers num="3.1-10" edition=""/>
        <vers num="3.1-10" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="kdelibs_devel">
        <vers num="2.1.1-5" edition=""/>
        <vers num="2.1.1-5" edition=":i386_dev"/>
        <vers num="2.2-11" edition=""/>
        <vers num="2.2-11" edition=":ia64_dev"/>
        <vers num="2.2-11" edition=":i386_dev"/>
        <vers num="3.0.0-10" edition=""/>
        <vers num="3.0.0-10" edition=":i386_dev"/>
        <vers num="3.0.3-8" edition=""/>
        <vers num="3.0.3-8" edition=":i386_dev"/>
        <vers num="3.1-10" edition=""/>
        <vers num="3.1-10" edition=":i386_dev"/>
      </prod>
      <prod vendor="redhat" name="kdelibs_sound">
        <vers num="2.1.1-5" edition=""/>
        <vers num="2.1.1-5" edition=":i386_sound"/>
        <vers num="2.2-11" edition=""/>
        <vers num="2.2-11" edition=":i386_sound"/>
        <vers num="2.2-11" edition=":ia64_sound"/>
      </prod>
      <prod vendor="redhat" name="kdelibs_sound_devel">
        <vers num="2.1.1-5" edition=""/>
        <vers num="2.1.1-5" edition=":i386_sound_dev"/>
        <vers num="2.2-11" edition=""/>
        <vers num="2.2-11" edition=":ia64_sound_dev"/>
        <vers num="2.2-11" edition=":i386_sound_dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0460" published="2003-08-27" name="CVE-2003-0460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/694428" source="CERT-VN">VU#694428</ref>
      <ref url="http://www.apache.org/dist/httpd/Announcement.html" source="CONFIRM" patch="1">http://www.apache.org/dist/httpd/Announcement.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="1.3.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0461" published="2003-08-27" name="CVE-2003-0461" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT">RHSA-2004:188</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html" source="MISC">http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9330" source="OVAL">oval:org.mitre.oval:def:9330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:997" source="OVAL" sig="1">oval:org.mitre.oval:def:997</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:304" source="OVAL" sig="1">oval:org.mitre.oval:def:304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0462" published="2003-08-27" name="CVE-2003-0462" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:309" source="OVAL" sig="1">oval:org.mitre.oval:def:309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="8.2" edition=""/>
        <vers num="8.2" edition=":ppc"/>
        <vers num="9.0"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0463" reject="1" published="2003-12-31" name="CVE-2003-0463" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0464" published="2003-08-27" name="CVE-2003-0464" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:311" source="OVAL" sig="1">oval:org.mitre.oval:def:311</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0465" published="2003-08-18" name="CVE-2003-0465" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as opposed to the expected behavior of strncpy as implemented in libc, which could lead to information leaks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT" patch="1" adv="1">RHSA-2004:188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10285" source="OVAL">oval:org.mitre.oval:def:10285</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796415223490&amp;w=2" source="CONFIRM" adv="1">http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796415223490&amp;w=2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796021120436&amp;w=2" source="CONFIRM" adv="1">http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=105796021120436&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0466" published="2003-08-27" name="CVE-2003-0466" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/743092" source="CERT-VN" adv="1">VU#743092</ref>
      <ref url="http://www.securityfocus.com/bid/8315" source="BID" patch="1" adv="1">8315</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12785" source="XF">libc-realpath-offbyone-bo(12785)</ref>
      <ref url="http://www.turbolinux.com/security/TLSA-2003-46.txt" source="TURBO">TLSA-2003-46</ref>
      <ref url="http://www.securityfocus.com/archive/1/425061/100/0/threaded" source="BUGTRAQ">20060214 Re: Latest wu-ftpd exploit :-s</ref>
      <ref url="http://www.securityfocus.com/archive/1/424852/100/0/threaded" source="BUGTRAQ">20060213 Latest wu-ftpd exploit :-s</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-246.html" source="REDHAT">RHSA-2003:246</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-245.html" source="REDHAT">RHSA-2003:245</ref>
      <ref url="http://www.osvdb.org/6602" source="OSVDB">6602</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_032_wuftpd.html" source="SUSE">SuSE-SA:2003:032</ref>
      <ref url="http://www.debian.org/security/2003/dsa-357" source="DEBIAN">DSA-357</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001257.1-1" source="SUNALERT">1001257</ref>
      <ref url="http://securitytracker.com/id?1007380" source="SECTRACK">1007380</ref>
      <ref url="http://secunia.com/advisories/9535" source="SECUNIA">9535</ref>
      <ref url="http://secunia.com/advisories/9447" source="SECUNIA">9447</ref>
      <ref url="http://secunia.com/advisories/9446" source="SECUNIA">9446</ref>
      <ref url="http://secunia.com/advisories/9423" source="SECUNIA">9423</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106002488209129&amp;w=2" source="BUGTRAQ">20030804 Off-by-one Buffer Overflow Vulnerability in BSD libc realpath(3)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001702232325&amp;w=2" source="BUGTRAQ">20030804 wu-ftpd-2.6.2 off-by-one remote exploit.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001410028809&amp;w=2" source="FREEBSD">FreeBSD-SA-03:08</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105967301604815&amp;w=2" source="BUGTRAQ" adv="1">20030731 wu-ftpd fb_realpath() off-by-one bug</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-019-01" source="IMMUNIX">IMNX-2003-7+-019-01</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0065.html" source="VULNWATCH" adv="1">20030731 wu-ftpd fb_realpath() off-by-one bug</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-011.txt.asc" source="NETBSD">NetBSD-SA2003-011.txt.asc</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:080" source="MANDRAKE">MDKSA-2003:080</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1970" source="OVAL" sig="1">oval:org.mitre.oval:def:1970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="wu_ftpd">
        <vers num="2.6.1-16" edition=""/>
        <vers num="2.6.1-16" edition=":powerpc"/>
        <vers num="2.6.1-16" edition=":i386"/>
        <vers num="2.6.1-18" edition=""/>
        <vers num="2.6.1-18" edition=":ia64"/>
        <vers num="2.6.1-18" edition=":i386"/>
        <vers num="2.6.2-5" edition=""/>
        <vers num="2.6.2-5" edition=":i386"/>
        <vers num="2.6.2-8" edition=""/>
        <vers num="2.6.2-8" edition=":i386"/>
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.6"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="stable"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0467" published="2003-08-27" name="CVE-2003-0467" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105985703724758&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030802 [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0468" published="2003-08-27" name="CVE-2003-0468" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-363" source="DEBIAN" patch="1" adv="1">DSA-363</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001525130257&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref url="http://www.securityfocus.com/bid/8333" source="BID">8333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-251.html" source="REDHAT">RHSA-2003:251</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_033_postfix.html" source="SUSE">SuSE-SA:2003:033</ref>
      <ref url="http://secunia.com/advisories/9433" source="SECUNIA">9433</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081" source="MANDRAKE">MDKSA-2003:081</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717" source="CONECTIVA">CLA-2003:717</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:522" source="OVAL" sig="1">oval:org.mitre.oval:def:522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wietse_venema" name="postfix">
        <vers num="1.0.21"/>
        <vers num="1.1.11"/>
        <vers num="1999-09-06"/>
        <vers num="1999-12-31"/>
        <vers num="2000-02-28"/>
        <vers num="2001-11-15"/>
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0469" published="2003-08-07" name="CVE-2003-0469" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/823260" source="CERT-VN">VU#823260</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-14.html" source="CERT">CA-2003-14</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-023.asp" source="MS" patch="1" adv="1">MS03-023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105639925122961&amp;w=2" source="BUGTRAQ">20030622 Internet Explorer >=5.0 : Buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006067.html" source="FULLDISC">20030625 Re: Internet Explorer >=5.0 : Buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006155.html" source="FULLDISC">20030701 PoC for Internet Explorer >=5.0 buffer overflow (trivial exploit for hard case).</ref>
      <ref url="http://www.securityfocus.com/bid/8016" source="BID">8016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit"/>
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":server"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0470" published="2003-08-07" name="CVE-2003-0470" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/527228" source="CERT-VN">VU#527228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105647537823877&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030624 [Symantec Security Advisor] Symantec Security Check ActiveX Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12423" source="XF">symantec-security-activex-bo(12423)</ref>
      <ref url="http://www.securityfocus.com/bid/8008" source="BID">8008</ref>
      <ref url="http://securitytracker.com/id?1007029" source="SECTRACK">1007029</ref>
      <ref url="http://secunia.com/advisories/9091" source="SECUNIA">9091</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html" source="FULLDISC">20030622 Symantec ActiveX control buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="security_check">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0471" published="2003-08-07" name="CVE-2003-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105647081418155&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030624 Remote Buffer Overrun WebAdmin.exe</ref>
      <ref url="http://www.securityfocus.com/bid/8024" source="BID">8024</ref>
      <ref url="http://www.osvdb.org/2207" source="OSVDB">2207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105648385900792&amp;w=2" source="BUGTRAQ">20030624 Re: WebAdmin from ALT-N remote exploit PoC</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="webadmin">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0472" published="2003-08-07" name="CVE-2003-0472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IPv6 capability in IRIX 6.5.19 allows remote attackers to cause a denial of service (hang) in inetd via port scanning.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" source="SGI" patch="1" adv="1">20030607-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12676" source="XF">irix-inetd-portscan-dos(12676)</ref>
      <ref url="http://www.securityfocus.com/bid/8027" source="BID">8027</ref>
      <ref url="http://www.osvdb.org/8585" source="OSVDB">8585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0473" published="2003-08-07" name="CVE-2003-0473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" source="SGI" patch="1" adv="1">20030607-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12677" source="XF">irix-snoop-gain-privileges(12677)</ref>
      <ref url="http://www.securityfocus.com/bid/8029" source="BID">8029</ref>
      <ref url="http://www.osvdb.org/8586" source="OSVDB">8586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0474" published="2003-08-07" name="CVE-2003-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673543626636&amp;w=2" source="BUGTRAQ" adv="1">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105049794801319&amp;w=2" source="BUGTRAQ" adv="1">20030416 SFAD03-001: iWeb Mini Web Server Remote Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashley_brown" name="iweb_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0475" published="2003-08-07" name="CVE-2003-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673543626636&amp;w=2" source="BUGTRAQ" adv="1">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105640001823769&amp;w=2" source="BUGTRAQ" adv="1">20030623 TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashley_brown" name="iweb_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0476" published="2003-08-07" name="CVE-2003-0476" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-368.html" source="REDHAT" patch="1" adv="1">RHSA-2003:368</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-408.html" source="REDHAT">RHSA-2003:408</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074" source="MANDRAKE">MDKSA-2003:074</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105664924024009&amp;w=2" source="BUGTRAQ">20030626 Linux 2.4.x execve() file read race vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:327" source="OVAL" sig="1">oval:org.mitre.oval:def:327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0477" published="2003-08-07" name="CVE-2003-0477" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wzdftpd.net/changea.html" source="CONFIRM" patch="1" adv="1">http://www.wzdftpd.net/changea.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105674242105302&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030627 wzdftpd remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wzdftpd" name="wzdftpd">
        <vers prev="1" num="0.1_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0478" published="2003-08-07" name="CVE-2003-0478" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673555726823&amp;w=2" source="BUGTRAQ">20030627 Bahamut DoS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673489525906&amp;w=2" source="BUGTRAQ">20030627 Re: Bahamut IRCd &lt;= 1.4.35 and several derived daemons</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105665996104723&amp;w=2" source="BUGTRAQ">20030626 Bahamut IRCd &lt;= 1.4.35 and several derived daemons</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andromede" name="adromedeircd">
        <vers num="1.2.3"/>
      </prod>
      <prod vendor="daniel_moss" name="methane">
        <vers num="0.1.1"/>
      </prod>
      <prod vendor="hans_westerhof" name="digatech">
        <vers num="1.2.1"/>
      </prod>
      <prod vendor="wenet" name="ircd-ru">
        <vers num=""/>
      </prod>
      <prod vendor="bahamut" name="ircd">
        <vers prev="1" num="1.4.35"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0479" published="2003-08-07" name="CVE-2003-0479" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673452325230&amp;w=2" source="BUGTRAQ" adv="1">20030627 WebBBS Guestbook : Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="affordable_web_space_design" name="affordable_web_space_design_webbbs">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0480" published="2003-08-07" name="CVE-2003-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105673688529147&amp;w=2" source="BUGTRAQ">20030627 VMware Workstation 4.0: Possible privilege escalation on the host</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0481" published="2003-08-07" name="CVE-2003-0481" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638743109781&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030623 [KSA-001] Multiple vulnerabilities in Tutos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gero_kohnert" name="tutos">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0482" published="2003-08-07" name="CVE-2003-0482" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638743109781&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030623 [KSA-001] Multiple vulnerabilities in Tutos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gero_kohnert" name="tutos">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0483" published="2003-08-07" name="CVE-2003-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105638720409307&amp;w=2" source="BUGTRAQ">20030623 Many XSS Vulnerabilities in XMB Forum.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0484" published="2003-08-07" name="CVE-2003-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105639883722514&amp;w=2" source="BUGTRAQ">20030621 XSS Exploit In phpBB viewtopic.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0485" published="2003-08-07" name="CVE-2003-0485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7997" source="BID" adv="1">7997</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105613243117155&amp;w=2" source="BUGTRAQ" adv="1">20030620 SRT2003-06-20-1232 - Progress 4GL Compiler datatype overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="progress" name="4gl_compiler">
        <vers num="9.1" edition="d06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0486" published="2003-08-07" name="CVE-2003-0486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12366" source="XF" patch="1" adv="1">phpbb-viewtopic-sql-injection(12366)</ref>
      <ref url="http://www.securityfocus.com/bid/7979" source="BID" patch="1" adv="1">7979</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?t=112052" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=112052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105607263130644&amp;w=2" source="BUGTRAQ">20030619 phpBB password disclosure by sql injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0487" published="2003-08-07" name="CVE-2003-0487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7967" source="BID" patch="1" adv="1">7967</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12368" source="XF" adv="1">kerio-multiple-modules-bo(12368)</ref>
      <ref url="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" source="MISC" adv="1">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105596982503760&amp;w=2" source="BUGTRAQ" adv="1">20030618 Multiple buffer overflows and XSS in Kerio MailServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0488" published="2003-08-07" name="CVE-2003-0488" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7968" source="BID" patch="1" adv="1">7968</ref>
      <ref url="http://www.securityfocus.com/bid/7966" source="BID" patch="1" adv="1">7966</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12367" source="XF" adv="1">kerio-multiple-modules-xss(12367)</ref>
      <ref url="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" source="MISC" adv="1">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105596982503760&amp;w=2" source="BUGTRAQ" adv="1">20030618 Multiple buffer overflows and XSS in Kerio MailServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0489" published="2003-08-07" name="CVE-2003-0489" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-330" source="DEBIAN" patch="1" adv="1">DSA-330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_c._toren" name="tcptraceroute">
        <vers prev="1" num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0490" published="2003-08-07" name="CVE-2003-0490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105579526026992&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030616 Dantz Retrospect Client 5.0.540 for Mac OS X - permission issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dantz" name="retrospect_client">
        <vers num="5.0.540"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0491" published="2003-08-07" name="CVE-2003-0491" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=105577873506147&amp;w=2" source="BUGTRAQ">20030616 Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials"</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=105577873506147&amp;w=2" source="VULN-DEV">20030614 Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mytutorials" name="tutorials">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0492" published="2003-08-07" name="CVE-2003-0492" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12325" source="XF" adv="1">snitz-search-xss(12325)</ref>
      <ref url="http://www.securityfocus.com/bid/7922" source="BID" adv="1">7922</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578322012128&amp;w=2" source="BUGTRAQ">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0493" published="2003-08-07" name="CVE-2003-0493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7924" source="BID" adv="1">7924</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578322012128&amp;w=2" source="BUGTRAQ" adv="1">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0494" published="2003-08-07" name="CVE-2003-0494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12326" source="XF" adv="1">snitz-forums-password-reset(12326)</ref>
      <ref url="http://www.securityfocus.com/bid/7925" source="BID" adv="1">7925</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578322012128&amp;w=2" source="BUGTRAQ" adv="1">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0495" published="2003-08-07" name="CVE-2003-0495" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12304" source="XF" adv="1">lednews-message-xss(12304)</ref>
      <ref url="http://www.securityfocus.com/bid/7920" source="BID">7920</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105578330812212&amp;w=2" source="BUGTRAQ" adv="1">20030615 XSS Vulnerability in LedNews (CGI/Perl) v0.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledscripts.com" name="lednews">
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0496" published="2003-08-18" name="CVE-2003-0496" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2003/a070803-1.txt" source="ATSTAKE" patch="1" adv="1">A070803-1</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html" source="VULNWATCH" patch="1" adv="1">20030709 Pipe Filename Local Privilege Escalation FAQ</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830986720243&amp;w=2" source="BUGTRAQ">20030715 CreateFile exploit, (working)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820282607865&amp;w=2" source="BUGTRAQ">20030714 @stake named pipe exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_terminal_services">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0497" published="2003-08-07" name="CVE-2003-0497" modified="2012-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=7" source="IDEFENSE">20030701 Caché Insecure Installation File and Directory Permissions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0498" published="2003-08-07" name="CVE-2003-0498" modified="2012-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=7" source="IDEFENSE">20030701 Caché Insecure Installation File and Directory Permissions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0499" published="2003-08-07" name="CVE-2003-0499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105700201923438&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.17.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0500" published="2003-08-07" name="CVE-2003-0500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-338" source="DEBIAN" patch="1" adv="1">DSA-338</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html" source="FULLDISC">20030618 SQL Inject in ProFTPD login against Postgresql using mod_sql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.9_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0501" published="2003-08-07" name="CVE-2003-0501" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT" patch="1" adv="1">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105621758104242" source="BUGTRAQ" adv="1">20030620 Linux /proc sensitive information disclosure</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:328" source="OVAL" sig="1">oval:org.mitre.oval:def:328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0502" published="2003-08-27" name="CVE-2003-0502" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.rapid7.com/advisories/R7-0015.html" source="MISC">http://www.rapid7.com/advisories/R7-0015.html </ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" source="VULNWATCH" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers prev="1" num="4.1.3g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0503" published="2003-08-07" name="CVE-2003-0503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105724538222772&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105725489003575&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</ref>
      <ref url="http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html" source="MISC">http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0504" published="2003-08-07" name="CVE-2003-0504" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718361607981&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 [KSA-003] Cross Site Scripting Vulnerability in Phpgroupware</ref>
      <ref url="http://www.security-corporation.com/articles-20030702-005.html" source="MISC">http://www.security-corporation.com/articles-20030702-005.html</ref>
      <ref url="http://www.debian.org/security/2003/dsa-365" source="DEBIAN">DSA-365</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:077" source="MANDRAKE">MDKSA-2003:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000697" source="CONECTIVA">CLA-2003:697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.14.003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0505" published="2003-08-07" name="CVE-2003-0505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/7931" source="BID" patch="1" adv="1">7931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105716650021546&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0506" published="2003-08-07" name="CVE-2003-0506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105716650021546&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0507" published="2003-08-07" name="CVE-2003-0507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/594108" source="CERT-VN">VU#594108</ref>
      <ref url="http://support.microsoft.com/default.aspx?kbid=319709" source="MSKB" patch="1" adv="1">Q319709</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105716669921775&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030702 CORE-2003-0305-03: Active Directory Stack Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/7930" source="BID">7930</ref>
      <ref url="http://secunia.com/advisories/9171" source="SECUNIA">9171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0508" published="2003-08-07" name="CVE-2003-0508" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105709569312583&amp;w=2" source="BUGTRAQ" adv="1">20030701 [sec-labs] Adobe Acrobat Reader &lt;=5.0.7 Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105785749721291&amp;w=2" source="BUGTRAQ">20030709 Acroread 5.0.7 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0509" published="2003-08-07" name="CVE-2003-0509" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105709450711395&amp;w=2" source="BUGTRAQ" adv="1">20030701 CyberStrong Shopping Cart - Advisory &amp; Exploit Code</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12485" source="XF">cyberstrongeshop-multiple-sql-injection(12485)</ref>
      <ref url="http://www.securityfocus.com/bid/14112" source="BID">14112</ref>
      <ref url="http://www.securityfocus.com/bid/14103" source="BID">14103</ref>
      <ref url="http://www.securityfocus.com/bid/14101" source="BID">14101</ref>
      <ref url="http://www.osvdb.org/10100" source="OSVDB">10100</ref>
      <ref url="http://www.osvdb.org/10099" source="OSVDB">10099</ref>
      <ref url="http://www.osvdb.org/10098" source="OSVDB">10098</ref>
      <ref url="http://securitytracker.com/id?1007092" source="SECTRACK">1007092</ref>
      <ref url="http://secunia.com/advisories/9165" source="SECUNIA">9165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyberstrong" name="eshop">
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0510" published="2003-08-07" name="CVE-2003-0510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105709355110281&amp;w=2" source="BUGTRAQ" adv="1">20030701 ezbounce[v1.0-(1.04a/1.50pre6)]: remote format string exploit.</ref>
      <ref url="http://druglord.freelsd.org/ezbounce/" source="CONFIRM">http://druglord.freelsd.org/ezbounce/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezbounce" name="ezbounce">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.2"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29"/>
        <vers num="1.3"/>
        <vers num="1.30"/>
        <vers num="1.31"/>
        <vers num="1.32"/>
        <vers num="1.33"/>
        <vers num="1.34"/>
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38"/>
        <vers num="1.39"/>
        <vers num="1.4"/>
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.5"/>
        <vers num="1.50"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0511" published="2003-08-27" name="CVE-2003-0511" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm" source="MISC">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030728-ap1x00.shtml" source="CISCO">20030728 HTTP GET Vulnerability in AP1x00</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5834" source="OVAL">oval:org.mitre.oval:def:5834</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0055.html" source="VULNWATCH" adv="1">20030728 Cisco Aironet AP 1100 Malformed HTTP Request Crash Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(11)ja"/>
        <vers num="12.2(4)ja"/>
        <vers num="12.2(4)ja1"/>
        <vers num="12.2(8)ja"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0512" published="2003-08-27" name="CVE-2003-0512" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/886796" source="CERT-VN">VU#886796</ref>
      <ref url="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm" source="MISC">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml" source="CISCO">20030724 Enumerating Locally Defined Users in Cisco IOS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5824" source="OVAL">oval:org.mitre.oval:def:5824</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0056.html" source="VULNWATCH" adv="1">20030728 Cisco Aironet AP1100 Valid Account Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(24)s1"/>
        <vers num="12.0(24.2)s"/>
        <vers num="12.2(11)ja1"/>
        <vers num="12.2(14.5)"/>
        <vers num="12.2(14.5)t"/>
        <vers num="12.2(15)zn"/>
        <vers num="12.2(15.1)s"/>
        <vers num="12.2(16)b"/>
        <vers num="12.2(16.1)b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0513" published="2004-04-15" name="CVE-2003-0513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.0.1" edition="sp4"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0514" published="2004-04-15" name="CVE-2003-0514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0515" published="2003-08-18" name="CVE-2003-0515" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-347" source="DEBIAN" patch="1" adv="1">DSA-347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teapop" name="teapop">
        <vers num="0.3.4"/>
        <vers num="0.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0516" published="2003-08-18" name="CVE-2003-0516" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" source="CONFIRM" patch="1">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gert_doering" name="mgetty">
        <vers prev="1" num="1.1.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0517" published="2003-08-18" name="CVE-2003-0517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" source="CONFIRM">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gert_doering" name="mgetty">
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
        <vers num="1.1.22"/>
        <vers prev="1" num="1.1.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0518" published="2003-08-18" name="CVE-2003-0518" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0187.html" source="BUGTRAQ" patch="1">20030715 FIXED: MacOSX - crash screensaver locked with password and get thedesktop back</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=120232" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=120232</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0034.html" source="BUGTRAQ" adv="1">20030704 MacOSX - crash screensaver locked with password and get the desktop back</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0519" published="2003-08-18" name="CVE-2003-0519" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006286.html" source="FULLDISC">20030707 Internet Explorer 6 DoS Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0520" published="2003-08-18" name="CVE-2003-0520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8107" source="BID" adv="1">8107</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105735714318026&amp;w=2" source="BUGTRAQ" adv="1">20030704 Trillian Remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="0.74"/>
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0521" published="2003-08-18" name="CVE-2003-0521" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
cPanel, cPanel, 7.0</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105760556627616&amp;w=2" source="BUGTRAQ" patch="1">20030706 cPanel Malicious HTML Tags Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.2"/>
        <vers num="6.4"/>
        <vers num="6.4.1"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2_stable_48"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0522" published="2003-08-18" name="CVE-2003-0522" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105760660928715&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030705 Re: Another ProductCart SQL Injection Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105733145930031&amp;w=2" source="BUGTRAQ" adv="1">20030704 Another ProductCart SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="1.5"/>
        <vers num="1.5002"/>
        <vers num="1.5003"/>
        <vers num="1.5003r"/>
        <vers num="1.5004"/>
        <vers num="1.6002"/>
        <vers num="1.6003"/>
        <vers num="1.6b"/>
        <vers num="1.6b001"/>
        <vers num="1.6b002"/>
        <vers num="1.6b003"/>
        <vers num="1.6br"/>
        <vers num="1.6br001"/>
        <vers num="1.6br003"/>
        <vers num="2"/>
        <vers num="2br000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0523" published="2003-08-18" name="CVE-2003-0523" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105761696706800&amp;w=2" source="BUGTRAQ" adv="1">20030705 ProductCart XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="early_impact" name="productcart">
        <vers num="1.5"/>
        <vers num="1.5002"/>
        <vers num="1.5003"/>
        <vers num="1.5003r"/>
        <vers num="1.5004"/>
        <vers num="1.6002"/>
        <vers num="1.6003"/>
        <vers num="1.6b"/>
        <vers num="1.6b001"/>
        <vers num="1.6b002"/>
        <vers num="1.6b003"/>
        <vers num="1.6br"/>
        <vers num="1.6br001"/>
        <vers num="1.6br003"/>
        <vers num="2"/>
        <vers num="2br000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0524" published="2003-08-18" name="CVE-2003-0524" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105769387706906&amp;w=2" source="BUGTRAQ" adv="1">20030708 Qt temporary files race condition in Knoppix 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knoppix" name="knoppix">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0525" published="2003-08-27" name="CVE-2003-0525" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12701" source="XF">winnt-file-management-dos (12701)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-029.asp" source="MS">MS03-029</ref>
      <ref url="http://www.atstake.com/research/advisories/2003/a072303-1.txt" source="ATSTAKE" adv="1">A072303-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:319" source="OVAL" sig="1">oval:org.mitre.oval:def:319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0526" published="2003-08-18" name="CVE-2003-0526" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-028.asp" source="MS">MS03-028</ref>
      <ref url="http://pivx.com/larholm/adv/TL006" source="MISC">http://pivx.com/larholm/adv/TL006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105838590030409&amp;w=2" source="NTBUGTRAQ">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838519729525&amp;w=2" source="BUGTRAQ">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html" source="VULNWATCH">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html" source="VULNWATCH" adv="1">20030716 ISA Server - Error Page Cross Site Scripting</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838862201266&amp;w=2" source="BUGTRAQ">20030716 ISA Server - Error Page Cross Site Scripting</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:117" source="OVAL" sig="1">oval:org.mitre.oval:def:117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="fp1"/>
        <vers num="2000" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0528" published="2003-09-17" name="CVE-2003-0528" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-23.html" source="CERT" patch="1" adv="1">CA-2003-23</ref>
      <ref url="http://www.kb.cert.org/vuls/id/254236" source="CERT-VN">VU#254236</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS03-039.asp" source="MS" patch="1" adv="1">MS03-039</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0306.htm" source="MISC">http://www.nsfocus.com/english/homepage/research/0306.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0100.html" source="VULNWATCH">20030911 NSFOCUS SA2003-06 : Microsoft Windows RPC DCOM Interface Heap Overflow Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106407417011430&amp;w=2" source="BUGTRAQ">20030920 The Analysis of RPC Long Filename Heap Overflow AND a Way to Write  Universal Heap Overflow of Windows</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3966" source="OVAL" sig="1">oval:org.mitre.oval:def:3966</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2968" source="OVAL" sig="1">oval:org.mitre.oval:def:2968</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2884" source="OVAL" sig="1">oval:org.mitre.oval:def:2884</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:127" source="OVAL" sig="1">oval:org.mitre.oval:def:127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0530" published="2003-08-27" name="CVE-2003-0530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/548964" source="CERT-VN">VU#548964</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-22.html" source="CERT">CA-2003-22</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS" patch="1" adv="1">MS03-032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12962" source="XF">ie-br549-activex-bo(12962)</ref>
      <ref url="http://www.securityfocus.com/bid/8454" source="BID" adv="1">8454</ref>
      <ref url="http://securitytracker.com/id?1007538" source="SECTRACK">1007538</ref>
      <ref url="http://secunia.com/advisories/9580" source="SECUNIA">9580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0531" published="2003-08-27" name="CVE-2003-0531" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/205148" source="CERT-VN">VU#205148</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-22.html" source="CERT">CA-2003-22</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS" patch="1" adv="1">MS03-032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12961" source="XF">ie-cache-script-injection(12961)</ref>
      <ref url="http://www.securityfocus.com/bid/8457" source="BID" adv="1">8457</ref>
      <ref url="http://www.lac.co.jp/security/english/snsadv_e/67_e.html" source="MISC">http://www.lac.co.jp/security/english/snsadv_e/67_e.html</ref>
      <ref url="http://secunia.com/advisories/9580" source="SECUNIA">9580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0532" published="2003-08-27" name="CVE-2003-0532" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/865940" source="CERT-VN" adv="1">VU#865940</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms03-032.asp" source="MS">MS03-032</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20030820.html" source="MISC">http://www.eeye.com/html/Research/Advisories/AD20030820.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106149026621753&amp;w=2" source="BUGTRAQ" adv="1">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html" source="VULNWATCH" adv="1">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0533" published="2004-06-01" name="CVE-2003-0533" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/753212" source="CERT-VN" patch="1" adv="1">VU#753212</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413C.html" source="EEYE">AD20040413C</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108325860431471&amp;w=2" source="BUGTRAQ">20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html" source="FULLDISC">20040413 EEYE: Windows Local Security Authority Service Remote Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15699" source="XF">win-lsass-bo(15699)</ref>
      <ref url="http://www.securityfocus.com/bid/10108" source="BID">10108</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:919" source="OVAL" sig="1">oval:org.mitre.oval:def:919</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:898" source="OVAL" sig="1">oval:org.mitre.oval:def:898</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:883" source="OVAL" sig="1">oval:org.mitre.oval:def:883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0535" published="2003-08-18" name="CVE-2003-0535" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-345" source="DEBIAN" patch="1" adv="1">DSA-345</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006386.html" source="FULLDISC">20030708 Fwd: xbl vulnerabilty</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xblockout" name="xbl">
        <vers num="1.0i"/>
        <vers num="1.0k"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0536" published="2003-08-18" name="CVE-2003-0536" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-346" source="DEBIAN" patch="1" adv="1">DSA-346</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105128606513226&amp;w=2" source="BUGTRAQ" adv="1">20030425 Unauthorized reading files on phpSysInfo</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsysinfo" name="phpsysinfo">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0537" published="2003-08-18" name="CVE-2003-0537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-341" source="DEBIAN" patch="1" adv="1">DSA-341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daiki_ueno" name="liece_emacs_irc_client">
        <vers prev="1" num="2.0_0.2003-05-27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0538" published="2003-08-18" name="CVE-2003-0538" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-342" source="DEBIAN" patch="1" adv="1">DSA-342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozart" name="mozart">
        <vers num="1.2.3"/>
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0539" published="2003-08-18" name="CVE-2003-0539" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-343" source="DEBIAN" patch="1" adv="1">DSA-343</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-242.html" source="REDHAT">RHSA-2003:242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:28" source="OVAL" sig="1">oval:org.mitre.oval:def:28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ddskk" name="ddskk">
        <vers num="11.6_.rel.0"/>
      </prod>
      <prod vendor="redhat" name="daredevil_skk">
        <vers num="11.3.2" edition=""/>
        <vers num="11.3.2" edition=":noarch"/>
        <vers num="11.3.5" edition=""/>
        <vers num="11.3.5" edition=":noarch"/>
        <vers num="11.6.0-10" edition=""/>
        <vers num="11.6.0-10" edition=":noarch"/>
        <vers num="11.6.0-6" edition=""/>
        <vers num="11.6.0-6" edition=":noarch"/>
        <vers num="11.6.0-8" edition=""/>
        <vers num="11.6.0-8" edition=":noarch"/>
      </prod>
      <prod vendor="redhat" name="ddskk-xemacs">
        <vers num="11.6.0-10" edition=""/>
        <vers num="11.6.0-10" edition=":noarch"/>
        <vers num="11.6.0-6" edition=""/>
        <vers num="11.6.0-6" edition=":noarch"/>
        <vers num="11.6.0-8" edition=""/>
        <vers num="11.6.0-8" edition=":noarch"/>
      </prod>
      <prod vendor="skk" name="skk">
        <vers num="10.62a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0540" published="2003-08-27" name="CVE-2003-0540" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/895508" source="CERT-VN">VU#895508</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-251.html" source="REDHAT" patch="1" adv="1">RHSA-2003:251</ref>
      <ref url="http://www.debian.org/security/2003/dsa-363" source="DEBIAN" patch="1" adv="1">DSA-363</ref>
      <ref url="http://www.securityfocus.com/bid/8333" source="BID">8333</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2003_033_postfix.html" source="SUSE">SuSE-SA:2003:033</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3517.html" source="ENGARDE">ESA-20030804-019</ref>
      <ref url="http://secunia.com/advisories/9433" source="SECUNIA">9433</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106029188614704&amp;w=2" source="TRUSTIX">2003-0029</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-August/007693.html" source="FULLDISC">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717" source="CONECTIVA">CLA-2003:717</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081" source="MANDRAKE">MDKSA-2003:081</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106001525130257&amp;w=2" source="BUGTRAQ">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:544" source="OVAL" sig="1">oval:org.mitre.oval:def:544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wietse_venema" name="postfix">
        <vers num="1.0.21"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1999-09-06"/>
        <vers num="1999-12-31"/>
        <vers num="2000-02-28"/>
        <vers num="2001-11-15"/>
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0541" published="2003-09-17" name="CVE-2003-0541" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-264.html" source="REDHAT" patch="1" adv="1">RHSA-2003:264</ref>
      <ref url="http://www.debian.org/security/2005/dsa-710" source="DEBIAN">DSA-710</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:093" source="MANDRAKE">MDKSA-2003:093</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737" source="CONECTIVA">CLA-2003:737</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:148" source="OVAL" sig="1">oval:org.mitre.oval:def:148</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gtkhtml">
        <vers prev="1" num="1.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0542" published="2003-11-03" name="CVE-2003-0542" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/549142" source="CERT-VN">VU#549142</ref>
      <ref url="http://www.kb.cert.org/vuls/id/434566" source="CERT-VN">VU#434566</ref>
      <ref url="http://www.securityfocus.com/bid/8911" source="BID" patch="1" adv="1">8911</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-015.html" source="REDHAT" patch="1" adv="1">RHSA-2004:015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106761802305141&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20031031 GLSA:  apache (200310-04)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13400" source="XF">apache-modalias-modrewrite-bo(13400)</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://www.securityfocus.com/archive/1/342674" source="BUGTRAQ">20031028 [OpenPKG-SA-2003.046] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://www.securityfocus.com/advisories/6079" source="HP">HPSBUX0311-301</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-405.html" source="REDHAT">RHSA-2003:405</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-360.html" source="REDHAT">RHSA-2003:360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-320.html" source="REDHAT">RHSA-2003:320</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103" source="MANDRAKE">MDKSA-2003:103</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" source="SUNALERT">101841</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101444-1" source="SUNALERT">101444</ref>
      <ref url="http://secunia.com/advisories/10593" source="SECUNIA">10593</ref>
      <ref url="http://secunia.com/advisories/10580" source="SECUNIA">10580</ref>
      <ref url="http://secunia.com/advisories/10463" source="SECUNIA">10463</ref>
      <ref url="http://secunia.com/advisories/10264" source="SECUNIA">10264</ref>
      <ref url="http://secunia.com/advisories/10260" source="SECUNIA">10260</ref>
      <ref url="http://secunia.com/advisories/10153" source="SECUNIA">10153</ref>
      <ref url="http://secunia.com/advisories/10114" source="SECUNIA">10114</ref>
      <ref url="http://secunia.com/advisories/10112" source="SECUNIA">10112</ref>
      <ref url="http://secunia.com/advisories/10102" source="SECUNIA">10102</ref>
      <ref url="http://secunia.com/advisories/10098" source="SECUNIA">10098</ref>
      <ref url="http://secunia.com/advisories/10096" source="SECUNIA">10096</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9458" source="OVAL">oval:org.mitre.oval:def:9458</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
      <ref url="http://httpd.apache.org/dist/httpd/Announcement2.html" source="CONFIRM">http://httpd.apache.org/dist/httpd/Announcement2.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20031203-01-U.asc" source="SGI">20031203-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt" source="SCO">SCOSA-2004.6</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:864" source="OVAL" sig="1">oval:org.mitre.oval:def:864</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:863" source="OVAL" sig="1">oval:org.mitre.oval:def:863</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3799" source="OVAL" sig="1">oval:org.mitre.oval:def:3799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.9"/>
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0543" published="2003-11-17" name="CVE-2003-0543" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/255484" source="CERT-VN">VU#255484</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-26.html" source="CERT">CA-2003-26</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-291.html" source="REDHAT" patch="1" adv="1">RHSA-2003:291</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3900" source="VUPEN">ADV-2006-3900</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm" source="MISC">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-292.html" source="REDHAT">RHSA-2003:292</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html" source="ENGARDE">ESA-20030930-027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-394" source="DEBIAN">DSA-394</ref>
      <ref url="http://www.debian.org/security/2003/dsa-393" source="DEBIAN">DSA-393</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1" source="SUNALERT">201029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5292" source="OVAL">oval:org.mitre.oval:def:5292</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" source="CONFIRM" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref url="http://secunia.com/advisories/22249" source="SECUNIA">22249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4254" source="OVAL" sig="1">oval:org.mitre.oval:def:4254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0544" published="2003-11-17" name="CVE-2003-0544" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/380864" source="CERT-VN">VU#380864</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-26.html" source="CERT">CA-2003-26</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-292.html" source="REDHAT" patch="1" adv="1">RHSA-2003:292</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-291.html" source="REDHAT" patch="1" adv="1">RHSA-2003:291</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3900" source="VUPEN">ADV-2006-3900</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm" source="MISC">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html" source="ENGARDE">ESA-20030930-027</ref>
      <ref url="http://www.debian.org/security/2003/dsa-394" source="DEBIAN">DSA-394</ref>
      <ref url="http://www.debian.org/security/2003/dsa-393" source="DEBIAN">DSA-393</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1" source="SUNALERT">201029</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43041" source="XF">openssl-asn1-sslclient-dos(43041)</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref url="http://secunia.com/advisories/22249" source="SECUNIA">22249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4574" source="OVAL" sig="1">oval:org.mitre.oval:def:4574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0545" published="2003-11-17" name="CVE-2003-0545" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/935264" source="CERT-VN">VU#935264</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-26.html" source="CERT">CA-2003-26</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-292.html" source="REDHAT" patch="1" adv="1">RHSA-2003:292</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3900" source="VUPEN">ADV-2006-3900</ref>
      <ref url="http://www.securityfocus.com/bid/8732" source="BID">8732</ref>
      <ref url="http://www.debian.org/security/2003/dsa-394" source="DEBIAN">DSA-394</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref url="http://secunia.com/advisories/22249" source="SECUNIA" adv="1">22249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2590" source="OVAL" sig="1">oval:org.mitre.oval:def:2590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0546" published="2003-08-27" name="CVE-2003-0546" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106036724315539&amp;w=2" source="REDHAT" patch="1" adv="1">RHSA-2003:255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:631" source="OVAL" sig="1">oval:org.mitre.oval:def:631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="up2date">
        <vers num="3.0.7-1" edition=""/>
        <vers num="3.0.7-1" edition=":i386"/>
        <vers num="3.0.7-1" edition=":i386_gnome"/>
        <vers num="3.1.23-1" edition=""/>
        <vers num="3.1.23-1" edition=":i386_gnome"/>
        <vers num="3.1.23-1" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2003-0547" published="2003-08-27" name="CVE-2003-0547" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-258.html" source="REDHAT" patch="1" adv="1">RHSA-2003:258</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106194792924122&amp;w=2" source="BUGTRAQ">20030824 [slackware-security]  GDM security update (SSA:2003-236-01)</ref>
      <ref url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" source="CONFIRM">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" source="CONECTIVA">CLA-2003:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:112" source="OVAL" sig="1">oval:org.mitre.oval:def:112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="2.4.0.7.13" edition=""/>
        <vers num="2.4.0.7.13" edition=":i386"/>
        <vers num="2.4.1.3.5" edition=""/>
        <vers num="2.4.1.3.5" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0548" published="2003-08-27" name="CVE-2003-0548" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-259.html" source="REDHAT" patch="1" adv="1">RHSA-2003:259</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-258.html" source="REDHAT" patch="1" adv="1">RHSA-2003:258</ref>
      <ref url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" source="CONFIRM">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" source="CONECTIVA">CLA-2003:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:113" source="OVAL" sig="1">oval:org.mitre.oval:def:113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.2.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="2.0_beta2.45" edition=""/>
        <vers num="2.0_beta2.45" edition=":ppc"/>
        <vers num="2.0_beta2.45" edition=":i386"/>
        <vers num="2.2.3.1.20" edition=""/>
        <vers num="2.2.3.1.20" edition=":ia64"/>
        <vers num="2.2.3.1.20" edition=":i386"/>
        <vers num="2.2.3.1.22" edition=""/>
        <vers num="2.2.3.1.22" edition=":i386"/>
        <vers num="2.4.0.7.13" edition=""/>
        <vers num="2.4.0.7.13" edition=":i386"/>
        <vers num="2.4.1.3.5" edition=""/>
        <vers num="2.4.1.3.5" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation_ia64"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0549" published="2003-08-27" name="CVE-2003-0549" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-259.html" source="REDHAT" patch="1" adv="1">RHSA-2003:259</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-258.html" source="REDHAT" patch="1" adv="1">RHSA-2003:258</ref>
      <ref url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html" source="CONFIRM">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729" source="CONECTIVA">CLA-2003:729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:129" source="OVAL" sig="1">oval:org.mitre.oval:def:129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.2.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
      </prod>
      <prod vendor="redhat" name="kdebase">
        <vers num="2.0_beta2.45" edition=""/>
        <vers num="2.0_beta2.45" edition=":ppc"/>
        <vers num="2.0_beta2.45" edition=":i386"/>
        <vers num="2.2.3.1.20" edition=""/>
        <vers num="2.2.3.1.20" edition=":ia64"/>
        <vers num="2.2.3.1.20" edition=":i386"/>
        <vers num="2.2.3.1.22" edition=""/>
        <vers num="2.2.3.1.22" edition=":i386"/>
        <vers num="2.4.0.7.13" edition=""/>
        <vers num="2.4.0.7.13" edition=":i386"/>
        <vers num="2.4.1.3.5" edition=""/>
        <vers num="2.4.1.3.5" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation_ia64"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0550" published="2003-08-27" name="CVE-2003-0550" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:380" source="OVAL" sig="1">oval:org.mitre.oval:def:380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0551" published="2003-08-27" name="CVE-2003-0551" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:384" source="OVAL" sig="1">oval:org.mitre.oval:def:384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0552" published="2003-08-27" name="CVE-2003-0552" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-238.html" source="REDHAT" patch="1" adv="1">RHSA-2003:238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-198.html" source="REDHAT" patch="1" adv="1">RHSA-2003:198</ref>
      <ref url="http://www.debian.org/security/2004/dsa-423" source="DEBIAN" patch="1" adv="1">DSA-423</ref>
      <ref url="http://www.debian.org/security/2004/dsa-358" source="DEBIAN">DSA-358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2003-239.html" source="REDHAT">RHSA-2003:239</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:385" source="OVAL" sig="1">oval:org.mitre.oval:def:385</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0553" published="2003-08-18" name="CVE-2003-0553" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820193406838&amp;w=2" source="BUGTRAQ" adv="1">20030714 Netscape 7.02 Client Detection Tool plug-in buffer overrun</ref>
      <ref url="http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf" source="MISC">http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0554" published="2003-08-18" name="CVE-2003-0554" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820316708258&amp;w=2" source="BUGTRAQ" adv="1">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006505.html" source="FULLDISC">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neomodus" name="direct_connect">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0555" published="2003-08-18" name="CVE-2003-0555" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105820576111599&amp;w=2" source="BUGTRAQ" adv="1">20030714 ImageMagick's Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0556" published="2003-08-18" name="CVE-2003-0556" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105804648003163&amp;w=2" source="BUGTRAQ" adv="1">20030712 DoS - Polycom MGC 25 Control Port</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006494.html" source="FULLDISC">20030712 DoS - Polycom MGC 25 Control Port</ref>
    </refs>
    <vuln_soft>
      <prod vendor="polycom" name="mgc-100">
        <vers num=""/>
      </prod>
      <prod vendor="polycom" name="mgc-25">
        <vers num="5.51.21"/>
        <vers num="5.51.211"/>
      </prod>
      <prod vendor="polycom" name="mgc-50">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0557" published="2003-08-18" name="CVE-2003-0557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.</descript>
    </desc>
    <sols>
      <sol source="nvd">This issue was addressed in a hot fix for StoreFront 6.1 in late January 2004.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105804683203384&amp;w=2" source="BUGTRAQ">20030712 ZH2003-3SA (security advisory): Storefront sql injection: users</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lagarde" name="storefront">
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0558" published="2003-08-18" name="CVE-2003-0558" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105795219412333&amp;w=2" source="BUGTRAQ" adv="1">20030711 LeapFTP remote buffer overflow exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leapware" name="leapftp">
        <vers num="2.7.3.600"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0559" published="2003-08-18" name="CVE-2003-0559" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105787021803729&amp;w=2" source="BUGTRAQ" adv="1">20030710 PHP-Include-Hack-Possibility in phpforum 2 RC-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpforum" name="phpforum">
        <vers num="2.0_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0560" published="2003-08-18" name="CVE-2003-0560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105733277731084&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030704 VPASP SQL Injection Vulnerability &amp; Exploit CODE</ref>
      <ref url="http://www.securityfocus.com/bid/8159" source="BID" adv="1">8159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_programming" name="vp-asp">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0561" published="2003-08-18" name="CVE-2003-0561" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105769805311484&amp;w=2" source="BUGTRAQ">20030707 Multiple Buffer Overflows in IglooFTP PRO</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0010.html" source="VULNWATCH">20030707 Multiple Buffer Overflows in IglooFTP PRO</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iglooftp" name="iglooftp_pro">
        <vers num="3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0562" published="2003-08-27" name="CVE-2003-0562" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/185593" source="CERT-VN">VU#185593</ref>
      <ref url="http://www.protego.dk/advisories/200301.html" source="MISC">http://www.protego.dk/advisories/200301.html</ref>
      <ref url="http://support.novell.com/servlet/tidfinder/2966549" source="CONFIRM">http://support.novell.com/servlet/tidfinder/2966549</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105897724931665&amp;w=2" source="BUGTRAQ" adv="1">20030723 Buffer Overflow in Netware Web Server PERL Handler</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0041.html" source="VULNWATCH">20030723 Buffer Overflow in Netware Web Server PERL Handler</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105897561229347&amp;w=2" source="BUGTRAQ">20030723 NOVL-2003-2966549 - Enterprise Web Server PERL Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" edition="sp4"/>
        <vers num="5.1" edition="sp6"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0564" published="2003-12-01" name="CVE-2003-0564" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/428230" source="CERT-VN" adv="1">VU#428230</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/smime.htm" source="MISC" patch="1" adv="1">http://www.uniras.gov.uk/vuls/2003/006489/smime.htm</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-110.html" source="REDHAT" patch="1" adv="1">RHSA-2004:110</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2" source="HP" patch="1" adv="1">SSRT4722</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13603" source="XF">smime-asn1-bo(13603)</ref>
      <ref url="http://www.securityfocus.com/bid/8981" source="BID" adv="1">8981</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-112.html" source="REDHAT">RHSA-2004:112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11462" source="OVAL">oval:org.mitre.oval:def:11462</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040402-01-U.asc" source="SGI">20040402-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" source="MANDRAKE">MDKSA-2004:021</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:914" source="OVAL" sig="1">oval:org.mitre.oval:def:914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:872" source="OVAL" sig="1">oval:org.mitre.oval:def:872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="groupmax_mail_-_security_option">
        <vers num="6.0"/>
      </prod>
      <prod vendor="hitachi" name="pki_runtime_library">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0565" published="2003-12-01" name="CVE-2003-0565" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927278" source="CERT-VN" adv="1">VU#927278</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2003/006489/x400.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2003/006489/x400.htm</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0567" published="2003-08-18" name="CVE-2003-0567" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2003-17.html" source="CERT" patch="1" adv="1">CA-2003-17</ref>
      <ref url="http://www.cert.org/advisories/CA-2003-15.html" source="CERT" patch="1" adv="1">CA-2003-15</ref>
      <ref url="http://www.kb.cert.org/vuls/id/411332" source="CERT-VN">VU#411332</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml" source="CISCO">20030717 IOS Interface Blocked by IPv4 Packet</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5603" source="OVAL">oval:org.mitre.oval:def:5603</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006743.html" source="FULLDISC">20030718 (no subject)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="11.0"/>
        <vers num="11.1"/>
        <vers num="11.1aa"/>
        <vers num="11.1ca"/>
        <vers num="11.1cc"/>
        <vers num="11.2"/>
        <vers num="11.2p"/>
        <vers num="11.2sa"/>
        <vers num="11.3"/>
        <vers num="11.3t"/>
        <vers num="12.0"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0sy"/>
        <vers num="12.0sz"/>
        <vers num="12.0t"/>
        <vers num="12.0w5"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xu"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1eb"/>
        <vers num="12.1ec"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1m"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xk"/>
        <vers num="12.1xl"/>
        <vers num="12.1xm"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1ye"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2bx"/>
        <vers num="12.2bz"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2ja"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2mx"/>
        <vers num="12.2s"/>
        <vers num="12.2sx"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xw"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zj"/>
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="3.0"/>
        <vers num="3.1_.0"/>
        <vers num="3.2_.0"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0572" published="2003-08-18" name="CVE-2003-0572" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12635" source="XF">irix-nsd-map-dos(12635)</ref>
      <ref url="http://www.osvdb.org/8587" source="OSVDB">8587</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0573" published="2003-08-18" name="CVE-2003-0573" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" source="SGI" patch="1" adv="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0574" published="2003-08-18" name="CVE-2003-0574" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030702-01-P" source="SGI" patch="1" adv="1">20030702-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17"/>
        <vers num="6.5.18"/>
        <vers num="6.5.19"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0575" published="2003-08-27" name="CVE-2003-0575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the name services daemon (nsd) in SGI IRIX 6.5.x through 6.5.21f, and possibly earlier versions, allows attackers to gain root privileges via the AUTH_UNIX gid list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/682900" source="CERT-VN">VU#682900</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030704-01-P" source="SGI" patch="1" adv="1">20030704-01-P</ref>
      <ref url="http://www.securityfocus.com/bid/8304" source="BID" adv="1">8304</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105958240709302&amp;w=2" source="BUGTRAQ" adv="1">20030730 [LSD] IRIX nsd remote buffer overflow vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/12763" source="XF">irix-authunix-nsd-bo(12763)</ref>
      <ref url="http://www.osvdb.org/2337" source="OSVDB">2337</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/n-130.shtml" source="CIAC">N-130</ref>
      <ref url="http://secunia.com/advisories/9390" source="SECUNIA">9390</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0576" published="2003-08-27" name="CVE-2003-0576" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, a different vulnerability than CVE-2003-0619.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030801-02-P" source="SGI">20030801-02-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030801-01-P" source="SGI">20030801-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0577" published="2003-08-18" name="CVE-2003-0577" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/6629" source="BID" patch="1" adv="1">6629</ref>
      <ref url="http://www.securityfocus.com/archive/1/306903" source="BUGTRAQ" patch="1">20030116 Re[2]: Local/remote mpg123 exploit</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000695" source="CONECTIVA" adv="1">CLA-2003:695</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt" source="SCO">CSSA-2004-002.0</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:078" source="MANDRAKE">MDKSA-2003:078</ref>
      <ref url="http://secunia.com/advisories/7875" source="SECUNIA">7875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59r"/>
        <vers num="pre0.59s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0578" published="2003-08-18" name="CVE-2003-0578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839150004682&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html" source="VULNWATCH" adv="1">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="u2_universe">
        <vers prev="1" num="10.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0579" published="2003-08-18" name="CVE-2003-0579" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html" source="VULNWATCH" adv="1">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105838948002337&amp;w=2" source="BUGTRAQ">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="u2_universe">
        <vers prev="1" num="10.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0580" published="2003-08-18" name="CVE-2003-0580" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0028.html" source="VULNWATCH" patch="1" adv="1">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839042603476&amp;w=2" source="BUGTRAQ">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="u2_universe">
        <vers prev="1" num="10.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0581" published="2003-08-18" name="CVE-2003-0581" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-360" source="DEBIAN" patch="1" adv="1">DSA-360</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105829691405446&amp;w=2" source="BUGTRAQ" adv="1">20030714 xfstt-1.4 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfstt" name="xfstt">
        <vers num="1.2.1"/>
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0582" reject="1" published="2003-12-31" name="CVE-2003-0582" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0504.  Reason: This candidate is a duplicate of CVE-2003-0504.  Notes: All CVE users should reference CVE-2003-0504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0583" published="2003-08-18" name="CVE-2003-0583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105846288808846&amp;w=2" source="BUGTRAQ" adv="1">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tolis_group" name="bru">
        <vers prev="1" num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0584" published="2003-08-18" name="CVE-2003-0584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105846288808846&amp;w=2" source="BUGTRAQ" adv="1">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tolis_group" name="bru">
        <vers prev="1" num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0585" published="2003-08-18" name="CVE-2003-0585" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105845898003616&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brooky" name="estore">
        <vers num="1.0.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0586" published="2003-08-18" name="CVE-2003-0586" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105845898003616&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brooky" name="estore">
        <vers num="1.0.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2003-0587" published="2003-08-18" name="CVE-2003-0587" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839276105934&amp;w=2" source="BUGTRAQ">20030716 Changing UBB cookie allows account hijack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopop" name="ultimate_bulletin_board">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0588" published="2003-08-18" name="CVE-2003-0588" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839007002993&amp;w=2" source="BUGTRAQ" adv="1">20030716 Digi-news and Digi-ads version 1.1 admin access without password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digi-fx" name="digi-news">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0589" published="2003-08-18" name="CVE-2003-0589" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105839007002993&amp;w=2" source="BUGTRAQ" adv="1">20030716 Digi-news and Digi-ads version 1.1 admin access without password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digi-fx" name="digi-news">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0590" published="2003-08-18" name="CVE-2003-0590" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://members.fortunecity.it/lethalman2002/bugs/splatt.html" source="MISC">http://members.fortunecity.it/lethalman2002/bugs/splatt.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105830019209609&amp;w=2" source="BUGTRAQ">20030715 Splatt Forum html injection code in post icon</ref>
    </refs>
    <vuln_soft>
      <prod vendor="splatt" name="splatt_forum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2003-0591" reject="1" published="2003-08-27" name="CVE-2003-0591" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a duplicate number that was created during the refinement phase.  Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0592" published="2004-04-15" name="CVE-2003-0592" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-074.html" source="REDHAT" patch="1" adv="1">RHSA-2004:074</ref>
      <ref url="http://www.debian.org/security/2004/dsa-459" source="DEBIAN" patch="1" adv="1">DSA-459</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:022" source="MANDRAKE">MDKSA-2004:022</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:823" source="OVAL" sig="1">oval:org.mitre.oval:def:823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.5"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
      <prod vendor="kde" name="konqueror_embedded">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0593" published="2004-04-15" name="CVE-2003-0593" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":linux"/>
        <vers num="5.0" edition=":mac"/>
        <vers num="5.0.2" edition=""/>
        <vers num="5.0.2" edition=":win32"/>
        <vers num="5.1.0" edition=""/>
        <vers num="5.1.0" edition=":win32"/>
        <vers num="5.1.1" edition=""/>
        <vers num="5.1.1" edition=":win32"/>
        <vers num="5.12" edition=""/>
        <vers num="5.12" edition=":win32"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":win32"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":win32"/>
        <vers num="6.0.1" edition=":linux"/>
        <vers num="6.0.2" edition=""/>
        <vers num="6.0.2" edition=":linux"/>
        <vers num="6.0.2" edition=":win32"/>
        <vers num="6.0.3" edition=""/>
        <vers num="6.0.3" edition=":linux"/>
        <vers num="6.0.3" edition=":win32"/>
        <vers num="6.0.4" edition=""/>
        <vers num="6.0.4" edition=":win32"/>
        <vers num="6.0.5" edition=""/>
        <vers num="6.0.5" edition=":win32"/>
        <vers num="6.0.6" edition=""/>
        <vers num="6.0.6" edition=":win32"/>
        <vers num="6.10" edition=""/>
        <vers num="6.10" edition=":linux"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":win32"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":win32"/>
        <vers num="7.0.3" edition=""/>
        <vers num="7.0.3" edition=":win32"/>
        <vers num="7.0_beta1" edition=""/>
        <vers num="7.0_beta1" edition=":win32"/>
        <vers num="7.0_beta2" edition=""/>
        <vers num="7.0_beta2" edition=":win32"/>
        <vers num="7.10"/>
        <vers num="7.11"/>
        <vers num="7.11b"/>
        <vers num="7.11j"/>
        <vers num="7.20"/>
        <vers num="7.20_beta1_build2981"/>
        <vers num="7.21"/>
        <vers num="7.22"/>
        <vers num="7.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0594" published="2004-04-15" name="CVE-2003-0594" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9826" source="OVAL">oval:org.mitre.oval:def:9826</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html" source="FULLDISC">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" source="VULNWATCH" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-112.html" source="REDHAT">RHSA-2004:112</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021" source="MANDRAKE">MDKSA-2004:021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:917" source="OVAL" sig="1">oval:org.mitre.oval:def:917</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:873" source="OVAL" sig="1">oval:org.mitre.oval:def:873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2003-0595" published="2003-08-27" name="CVE-2003-0595" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0038.html" source="VULNWATCH" adv="1">20030718 Witango &amp; Tango 2000 Application Server Remote System Buffer Overrun</ref>
    </refs>
    <vuln_soft>
      <prod vendor="witango" name="tango_server">
        <vers num="2000"/>
      